CyberSec.Space Logo
返回 CVE 浏览器

CVE-2004-1012

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1590%
EPSS Percentile26.00th
Published2005年1月10日
Last Modified2026年4月16日

Vulnerability Description

The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body.peek") and causes an index increment error that leads to an out-of-bounds memory corruption.

Affected Platforms (CPE)

📦
Carnegie Mellon University

Cyrus Imap Server

= 2.1.7
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.1.9
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.1.10
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.1.16
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.0_alpha
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.1_beta
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.2_beta
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.3
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.4
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.5
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.6
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.7
📦
Carnegie Mellon University

Cyrus Imap Server

= 2.2.8
📦
Openpkg

Openpkg

= current
💻
Conectiva

Linux

= 9.0
💻
Conectiva

Linux

= 10.0
💻
Redhat

Fedora Core

= core_2.0
💻
Redhat

Fedora Core

= core_3.0
💻
Trustix

Secure Linux

= 2.0
💻
Trustix

Secure Linux

= 2.1
💻
Trustix

Secure Linux

= 2.2
💻
Ubuntu

Ubuntu Linux

= 4.1
💻
Ubuntu

Ubuntu Linux

= 4.1

References & Advisories

相关漏洞威胁