Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16.
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Imap | Cyrus | * | 3.0.16 (excluding) |
Imap | Cyrus | 3.2.0 (including) | 3.2.8 (excluding) |
Imap | Cyrus | 3.4.0 (including) | 3.4.2 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | cyrus-imapd-0:3.0.7-20.el8_4.1 | * |
Red Hat Enterprise Linux 8.1 Extended Update Support | RedHat | cyrus-imapd-0:3.0.7-16.el8_1.1 | * |
Red Hat Enterprise Linux 8.2 Extended Update Support | RedHat | cyrus-imapd-0:3.0.7-16.el8_2.1 | * |
Cyrus-imapd | Ubuntu | bionic | * |
Cyrus-imapd | Ubuntu | esm-apps/bionic | * |
Cyrus-imapd | Ubuntu | esm-apps/focal | * |
Cyrus-imapd | Ubuntu | focal | * |
Cyrus-imapd | Ubuntu | trusty | * |
Cyrus-imapd | Ubuntu | upstream | * |
Cyrus-imapd | Ubuntu | xenial | * |
Cyrus-imapd-2.4 | Ubuntu | esm-apps/xenial | * |
Cyrus-imapd-2.4 | Ubuntu | trusty | * |
Cyrus-imapd-2.4 | Ubuntu | upstream | * |
Cyrus-imapd-2.4 | Ubuntu | xenial | * |