CVE-2015-8077: Integer Overflow
Integer overflow in the indexurlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the startoctet variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8077?
CVE-2015-8077 has a medium severity rating due to the potential impact of an integer overflow leading to unspecified consequences for remote attackers.
How do I fix CVE-2015-8077?
To fix CVE-2015-8077, upgrade to a patched version of Cyrus IMAP that addresses the integer overflow vulnerabilities.
Which versions of Cyrus IMAP are affected by CVE-2015-8077?
CVE-2015-8077 affects Cyrus IMAP versions 2.3.19, 2.4.18, and 2.5.6.
Can CVE-2015-8077 be exploited remotely?
Yes, CVE-2015-8077 can be exploited remotely by attackers to cause potential impact via specially crafted requests.
Is CVE-2015-8077 related to any earlier vulnerabilities?
Yes, CVE-2015-8077 is noted to exist due to an incomplete fix for a previous vulnerability.