CVE-2004-1067
CRITICAL
10.0
CVSS Severity Score
Vulnerability Description
Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username.
Affected Platforms (CPE)
📦
Carnegie Mellon University
Cyrus Imap Server
= 1.4📦
Carnegie Mellon University
Cyrus Imap Server
= 1.5.19📦
Carnegie Mellon University
Cyrus Imap Server
= 2.0.12📦
Carnegie Mellon University
Cyrus Imap Server
= 2.0.16📦
Carnegie Mellon University
Cyrus Imap Server
= 2.1.7📦
Carnegie Mellon University
Cyrus Imap Server
= 2.1.9📦
Carnegie Mellon University
Cyrus Imap Server
= 2.1.10📦
Carnegie Mellon University
Cyrus Imap Server
= 2.1.16📦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.0_alpha📦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.1_beta📦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.2_beta📦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.3📦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.4📦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.5📦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.6📦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.7📦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.8📦
Carnegie Mellon University
Cyrus Imap Server
= 2.2.9💻
Redhat
Fedora Core
= core_2.0💻
Redhat
Fedora Core
= core_3.0💻
Ubuntu
Ubuntu Linux
= 4.1💻
Ubuntu
