Vulnerability Description
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body.peek") and causes an index increment error that leads to an out-of-bounds memory corruption.
Affected Platforms (CPE)
π¦
Cyrus Imap Server
= 2.1.7π¦
Cyrus Imap Server
= 2.1.9π¦
Cyrus Imap Server
= 2.1.10π¦
Cyrus Imap Server
= 2.1.16π¦
Cyrus Imap Server
= 2.2.0_alphaπ¦
Cyrus Imap Server
= 2.2.1_betaπ¦
Cyrus Imap Server
= 2.2.2_betaπ¦
Cyrus Imap Server
= 2.2.3π¦
Cyrus Imap Server
= 2.2.4π¦
Cyrus Imap Server
= 2.2.5π¦
Cyrus Imap Server
= 2.2.6π¦
Cyrus Imap Server
= 2.2.7π¦
Cyrus Imap Server
= 2.2.8π»
Fedora Core
= core_2.0π»
Fedora Core
= core_3.0