CVE-2021-33582: High severity cyrus sasl vulnerability
Published Sep 1, 2021
·Updated
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16.
Affected Software
7 affected componentsFixes available
debian/cyrus-imapd
3.2.6-2+deb11u23.2.6-2+deb11u43.6.1-4+deb12u33.6.1-4+deb12u23.10.1-1
Cyrus IMAP<3.0.16
Cyrus IMAP>=3.2.0<3.2.8
Cyrus IMAP>=3.4.0<3.4.2
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Sep 1, 2021
CVE Published
via MITRE·05:32 AM
Data Sourced
via MITRE·05:32 AM
Description
Jan 23, 2025
Data Sourced
via Launchpad·06:43 PM
Description
Jan 27, 2025
Data Sourced
via Ubuntu·06:42 PM
RemedyDescriptionSeverityAffected Software