Description
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.
CVSS Metrics
- Vector
- AV:N/AC:L/Au:N/C:P/I:P/A:P
- Access Vector
- network
- Access Cmplx
- low
- Auth
- none
- Confidentiality
- partial
- Integrity
- partial
- Availability
- partial
- Weaknesses
- CWE-119CWE-200
Metadata
- Primary Vendor
- OPENSUSE
- Published
- 12/3/2015
- Last Modified
- 4/12/2025
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
opensuse : leapopensuse : opensusecyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imapcyrus : imap
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.