CVE-2004-1067
CRITICAL
10.0
CVSS Severity Score
Vulnerability Description
Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username.
Affected Platforms (CPE)
π¦
Carnegie Mellon University
Cyrus Imap Server
= 1.4π¦
Carnegie Mellon University
Cyrus Imap Server
= 1.5.19π¦
Carnegie Mellon University
Cyrus Imap Server
= 2.0.12π¦
Carnegie Mellon University
Cyrus Imap Server
= 2.0.16π¦
Carnegie Mellon University
Cyrus Imap Server
= 2.1.7π¦
Carnegie Mellon University
Cyrus Imap Server
= 2.1.9π¦
Carnegie Mellon University
Cyrus Imap Server
= 2.1.10π¦
Carnegie Mellon University
Cyrus Imap Server
= 2.1.16π¦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.0_alphaπ¦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.1_betaπ¦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.2_betaπ¦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.3π¦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.4π¦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.5π¦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.6π¦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.7π¦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.8π¦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.9π»
Redhat
Fedora Core
= core_2.0π»
Redhat
Fedora Core
= core_3.0π»
Ubuntu
Ubuntu Linux
= 4.1π»
Ubuntu
