Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24703
HistoryApr 10, 2020 - 1:02 a.m.

Arbitrary Code Execution

2020-04-1001:02:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.262 Low

EPSS

Percentile

96.8%

cyrus-imapd is vulnerable to arbitrary code execution. A buffer overflow flaw was found in the cyrus-imapd NNTP server, nntpd. A remote user able to use the nntpd service could use this flaw to crash the nntpd child process or, possibly, execute arbitrary code with the privileges of the cyrus user.

References