Lucene search

K
cve[email protected]CVE-2015-8076
HistoryDec 03, 2015 - 8:59 p.m.

CVE-2015-8076

2015-12-0320:59:07
CWE-119
CWE-200
web.nvd.nist.gov
33
cve-2015-8076
cyrus imap
index_urlfetch function
sensitive information
remote attackers
out-of-bounds heap read

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

4.3 Medium

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.1%

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.

Affected configurations

NVD
Node
opensuseleapMatch42.1
OR
opensuseopensuseMatch13.2
Node
cyrusimapMatch2.3.0
OR
cyrusimapMatch2.3.1
OR
cyrusimapMatch2.3.2
OR
cyrusimapMatch2.3.3
OR
cyrusimapMatch2.3.4
OR
cyrusimapMatch2.3.5
OR
cyrusimapMatch2.3.6
OR
cyrusimapMatch2.3.7
OR
cyrusimapMatch2.3.8
OR
cyrusimapMatch2.3.9
OR
cyrusimapMatch2.3.10
OR
cyrusimapMatch2.3.11
OR
cyrusimapMatch2.3.12
OR
cyrusimapMatch2.3.13
OR
cyrusimapMatch2.3.14
OR
cyrusimapMatch2.3.15
OR
cyrusimapMatch2.3.16
OR
cyrusimapMatch2.3.17
OR
cyrusimapMatch2.3.18
OR
cyrusimapMatch2.4.0
OR
cyrusimapMatch2.4.1
OR
cyrusimapMatch2.4.2
OR
cyrusimapMatch2.4.3
OR
cyrusimapMatch2.4.4
OR
cyrusimapMatch2.4.5
OR
cyrusimapMatch2.4.6
OR
cyrusimapMatch2.4.7
OR
cyrusimapMatch2.4.8
OR
cyrusimapMatch2.4.9
OR
cyrusimapMatch2.4.10
OR
cyrusimapMatch2.4.11
OR
cyrusimapMatch2.4.12
OR
cyrusimapMatch2.4.13
OR
cyrusimapMatch2.4.14
OR
cyrusimapMatch2.4.15
OR
cyrusimapMatch2.4.16
OR
cyrusimapMatch2.4.17
OR
cyrusimapMatch2.5.0
OR
cyrusimapMatch2.5.1
OR
cyrusimapMatch2.5.2
OR
cyrusimapMatch2.5.3

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

4.3 Medium

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.1%