CyberSec.Space Logo
CVEブラウザに戻る

CVE-2004-1067

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1850%
EPSS Percentile33.88th
Published2005年1月10日
Last Modified2026年4月16日

Vulnerability Description

Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username.

Affected Platforms (CPE)

📦
Carnegie Mellon University

Cyrus Imap Server

= 1.4
📦
Carnegie Mellon University

Cyrus Imap Server

= 1.5.19
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.0.12
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.0.16
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.1.7
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.1.9
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.1.10
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.1.16
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.0_alpha
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.1_beta
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.2_beta
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.3
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.4
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.5
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.6
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.7
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.8
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.9
💻
Redhat

Fedora Core

= core_2.0
💻
Redhat

Fedora Core

= core_3.0
💻
Ubuntu

Ubuntu Linux

= 4.1
💻
Ubuntu

Ubuntu Linux

= 4.1

References & Advisories

関連する脆弱性情報