Cyrus 2.0.15, 2.0.16, and 1.6.24 on BSDi 4.2, with IMAP enabled, allows remote attackers to cause a denial of service (hang) using PHP IMAP clients.
2001-08-30T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | carnegie_mellon_university | cyrus_imap_server | 1.6.24 | Yes |
Application | carnegie_mellon_university | cyrus_imap_server | 2.0.15 | Yes |
Application | carnegie_mellon_university | cyrus_imap_server | 2.0.16 | Yes |
Operating System | bsdi | bsd_os | 4.2 | Yes |