CyberSec.Space Logo
Back to CVE Browser

CVE-2004-1067

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1850%
EPSS Percentile33.88th
PublishedJan 10, 2005
Last ModifiedApr 16, 2026

Vulnerability Description

Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username.

Affected Platforms (CPE)

πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 1.4
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 1.5.19
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.0.12
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.0.16
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.1.7
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.1.9
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.1.10
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.1.16
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.0_alpha
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.1_beta
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.2_beta
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.3
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.4
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.5
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.6
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.7
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.8
πŸ“¦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.9
πŸ’»
Redhat

Fedora Core

= core_2.0
πŸ’»
Redhat

Fedora Core

= core_3.0
πŸ’»
Ubuntu

Ubuntu Linux

= 4.1
πŸ’»
Ubuntu

Ubuntu Linux

= 4.1

References & Advisories

Related Vulnerabilities