Lucene search

K
osvGoogleOSV:USN-4566-1
HistoryOct 05, 2020 - 5:25 p.m.

cyrus-imapd vulnerabilities

2020-10-0517:25:10
Google
osv.dev
9
cyrus imap server
vulnerabilities
http put operation
unauthorized mailbox creation
arbitrary code execution
sensitive information
software

AI Score

8

Confidence

High

EPSS

0.029

Percentile

90.8%

It was dicovered that Cyrus IMAP Server could execute arbitrary code via a
crafted HTTP PUT operation for an event with a long iCalendar property name.
An attacker could use this vulnerability to cause a crash or possibly execute
arbitrary code. (CVE-2019-11356)

It was discovered that the Cyrus IMAP Server allow users to create any
mailbox with administrative privileges. A local attacker could use this to
obtain sensitive information. (CVE-2019-19783)