Lucene search

K
cve[email protected]CVE-2011-3208
HistorySep 14, 2011 - 5:17 p.m.

CVE-2011-3208

2011-09-1417:17:07
CWE-119
web.nvd.nist.gov
53
cve-2011-3208
stack-based buffer overflow
nntpd.c
cyrus imap server
nvd
security vulnerability
remote code execution
nntp command

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.262 Low

EPSS

Percentile

96.8%

Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.

Affected configurations

NVD
Node
cmucyrus_imap_serverRange2.3.16
OR
cmucyrus_imap_serverMatch2.0.17
OR
cmucyrus_imap_serverMatch2.1.16
OR
cmucyrus_imap_serverMatch2.1.17
OR
cmucyrus_imap_serverMatch2.1.18
OR
cmucyrus_imap_serverMatch2.2.8
OR
cmucyrus_imap_serverMatch2.2.9
OR
cmucyrus_imap_serverMatch2.2.10
OR
cmucyrus_imap_serverMatch2.2.11
OR
cmucyrus_imap_serverMatch2.2.12
OR
cmucyrus_imap_serverMatch2.2.13
OR
cmucyrus_imap_serverMatch2.2.13p1
OR
cmucyrus_imap_serverMatch2.2.14
OR
cmucyrus_imap_serverMatch2.3.0
OR
cmucyrus_imap_serverMatch2.3.1
OR
cmucyrus_imap_serverMatch2.3.2
OR
cmucyrus_imap_serverMatch2.3.3
OR
cmucyrus_imap_serverMatch2.3.4
OR
cmucyrus_imap_serverMatch2.3.5
OR
cmucyrus_imap_serverMatch2.3.6
OR
cmucyrus_imap_serverMatch2.3.7
OR
cmucyrus_imap_serverMatch2.3.8
OR
cmucyrus_imap_serverMatch2.3.9
OR
cmucyrus_imap_serverMatch2.3.10
OR
cmucyrus_imap_serverMatch2.3.11
OR
cmucyrus_imap_serverMatch2.3.12
OR
cmucyrus_imap_serverMatch2.3.13
OR
cmucyrus_imap_serverMatch2.3.14
OR
cmucyrus_imap_serverMatch2.3.15
Node
cmucyrus_imap_serverMatch2.4.0
OR
cmucyrus_imap_serverMatch2.4.1
OR
cmucyrus_imap_serverMatch2.4.2
OR
cmucyrus_imap_serverMatch2.4.3
OR
cmucyrus_imap_serverMatch2.4.4
OR
cmucyrus_imap_serverMatch2.4.5
OR
cmucyrus_imap_serverMatch2.4.6
OR
cmucyrus_imap_serverMatch2.4.7
OR
cmucyrus_imap_serverMatch2.4.8
OR
cmucyrus_imap_serverMatch2.4.9
OR
cmucyrus_imap_serverMatch2.4.10

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.262 Low

EPSS

Percentile

96.8%