CVE-2017-12843: Input Validation
Published Aug 22, 2017
·Updated
Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.
Affected Software
2 affected components
cyrusimap Cyrus IMAP<=3.0.2
Fedoraproject Fedora=26
Event History
Aug 22, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12843?
CVE-2017-12843 has a medium severity rating, as it allows remote authenticated users to write to arbitrary files.
2
How do I fix CVE-2017-12843?
To fix CVE-2017-12843, upgrade Cyrus IMAP to version 3.0.3 or later.
3
Who is affected by CVE-2017-12843?
CVE-2017-12843 affects users of Cyrus IMAP versions prior to 3.0.3 and Fedora 26.
4
What types of commands exploit CVE-2017-12843?
CVE-2017-12843 can be exploited using crafted SYNCAPPLY, SYNCGET, or SYNCRESTORE commands.
5
What is the impact of CVE-2017-12843?
The impact of CVE-2017-12843 includes unauthorized file write access by remote authenticated users.