CVE-2004-1012: Critical severity Carnegie Mellon University Cyrus Imap Server vulnerability
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body.peek") and causes an index increment error that leads to an out-of-bounds memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1012?
CVE-2004-1012 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2004-1012?
To fix CVE-2004-1012, upgrade to Cyrus IMAP Server version 2.2.7 or later, as these versions include the patch addressing this vulnerability.
What versions of Cyrus IMAP Server are affected by CVE-2004-1012?
CVE-2004-1012 affects Cyrus IMAP Server versions 2.2.6 and earlier, including versions 2.1.7 through 2.2.6.
Can CVE-2004-1012 be exploited by an unauthenticated user?
No, CVE-2004-1012 requires that the attacker be a remote authenticated user to exploit the vulnerability.
What kind of attacks can CVE-2004-1012 facilitate?
CVE-2004-1012 can facilitate arbitrary code execution on the server, leading to potential data breaches or system compromise.