QID 375962
Date Published: 2021-11-03
QID 375962: Cyrus IMAP Server Access Control Vulnerability
Cyrus IMAP is an email, contacts and calendar server. Cyrus is free and open source.
Affected Version:
Cyrus IMAP version 3.4.0 and earlier
Cyrus IMAP version 3.2.6 and earlier
QID Detection Logic (Authenticated Unix):
This QID checks for vulnerable versions of Cyrus IMAP by executing "cyr_info version" command.
The vulnerability allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
Solution
The Vendor has released security update to fix the vulnerability.
For more information please visit the following links based on the version
Cyrus IMAP version 3.4.1 and
Cyrus IMAP version 3.2.7
Vendor References
- Cyrus IMAP 3.2.7 -
www.cyrusimap.org/imap/download/release-notes/3.2/x/3.2.7.html - Cyrus IMAP 3.4.1 -
www.cyrusimap.org/imap/download/release-notes/3.4/x/3.4.1.html
CVEs related to QID 375962
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-32056 |
|
||
| CVE-2021-32056 |
|