CVE-2015-8078: Integer Overflow
Integer overflow in the indexurlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the sectionoffset variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8078?
CVE-2015-8078 is classified as a moderate severity vulnerability due to its potential impact on affected systems.
How do I fix CVE-2015-8078?
To mitigate CVE-2015-8078, upgrade to a version of Cyrus IMAP that is not affected by this vulnerability.
Which versions of Cyrus IMAP are affected by CVE-2015-8078?
CVE-2015-8078 affects Cyrus IMAP versions 2.3.19, 2.4.18, and 2.5.6.
Can CVE-2015-8078 be exploited remotely?
Yes, CVE-2015-8078 can be exploited remotely by attackers to potentially affect the impacted systems.
What causes CVE-2015-8078?
CVE-2015-8078 is caused by an integer overflow in the index_urlfetch function within Cyrus IMAP.