Cyrus IMAP Server 'index_get_ids()' NULL Pointer Dereference Denial Of Service Vulnerability
BID:49659
Info
Cyrus IMAP Server 'index_get_ids()' NULL Pointer Dereference Denial Of Service Vulnerability
| Bugtraq ID: | 49659 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-3481 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2011 12:00AM |
| Updated: | Mar 23 2012 03:50PM |
| Credit: | John Capo and Øyvind Kolbu |
| Vulnerable: |
RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Enterprise Linux Desktop version 4 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Oracle Enterprise Linux 4 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Cyrus Cyrus IMAP Server 2.4.10 |
| Not Vulnerable: |
Cyrus Cyrus IMAP Server 2.4.11 |
Discussion
Cyrus IMAP Server 'index_get_ids()' NULL Pointer Dereference Denial Of Service Vulnerability
Cyrus IMAP Server is prone to a remote denial-of-service vulnerability caused by a NULL-pointer dereference.
Attackers can exploit this issue to cause the server to dereference an invalid memory location, resulting in a denial-of-service condition. Due to the nature of this issue, arbitrary code-execution may be possible; however, this has not been confirmed.
Versions prior to Cyrus IMAP Server 2.4.11 are vulnerable.
Cyrus IMAP Server is prone to a remote denial-of-service vulnerability caused by a NULL-pointer dereference.
Attackers can exploit this issue to cause the server to dereference an invalid memory location, resulting in a denial-of-service condition. Due to the nature of this issue, arbitrary code-execution may be possible; however, this has not been confirmed.
Versions prior to Cyrus IMAP Server 2.4.11 are vulnerable.
Exploit / POC
Cyrus IMAP Server 'index_get_ids()' NULL Pointer Dereference Denial Of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cyrus IMAP Server 'index_get_ids()' NULL Pointer Dereference Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.1
MandrakeSoft Enterprise Server 5 x86_64
Mandriva Linux Mandrake 2011 x86_64
Mandriva Linux Mandrake 2011
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2010.1 x86_64
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.1
-
Mandriva cyrus-imapd-2.3.15-10.4mdv2010.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-devel-2.3.15-10.4mdv2010.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-murder-2.3.15-10.4mdv2010.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-nntp-2.3.15-10.4mdv2010.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-utils-2.3.15-10.4mdv2010.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva perl-Cyrus-2.3.15-10.4mdv2010.2.i586.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva cyrus-imapd-2.3.12-0.p2.4.4mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-devel-2.3.12-0.p2.4.4mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-murder-2.3.12-0.p2.4.4mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-nntp-2.3.12-0.p2.4.4mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-utils-2.3.12-0.p2.4.4mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva perl-Cyrus-2.3.12-0.p2.4.4mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011 x86_64
-
Mandriva cyrus-imapd-2.3.16-7.2-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-devel-2.3.16-7.2-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-murder-2.3.16-7.2-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-nntp-2.3.16-7.2-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-utils-2.3.16-7.2-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva perl-Cyrus-2.3.16-7.2-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva cyrus-imapd-2.3.16-7.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-devel-2.3.16-7.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-murder-2.3.16-7.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-nntp-2.3.16-7.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-utils-2.3.16-7.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva perl-Cyrus-2.3.16-7.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva cyrus-imapd-2.3.12-0.p2.4.4mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-devel-2.3.12-0.p2.4.4mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-murder-2.3.12-0.p2.4.4mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-nntp-2.3.12-0.p2.4.4mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-utils-2.3.12-0.p2.4.4mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva perl-Cyrus-2.3.12-0.p2.4.4mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2010.1 x86_64
-
Mandriva cyrus-imapd-2.3.15-10.4mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-devel-2.3.15-10.4mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-murder-2.3.15-10.4mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-nntp-2.3.15-10.4mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva cyrus-imapd-utils-2.3.15-10.4mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva perl-Cyrus-2.3.15-10.4mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
Cyrus IMAP Server 'index_get_ids()' NULL Pointer Dereference Denial Of Service Vulnerability
References:
References:
- Bug 2772 - cmd_thread cores with bogus ids in references header (John Capo)
- Bug 3463 - Certain mails will crash imapd if using server side threading (�?yvind Kolbu)
- Cyrus Homepage (Project Cyrus)
- cyrus-imapd-2.4.11 released (Cyrus)
- GIT Commit: Bug #2772/3463 - fold references header (Bron Gondwana)