DSA-4458-1 cyrus-imapd -- security update

Related Vulnerabilities: CVE-2019-11356  

A flaw was discovered in the CalDAV feature in httpd of the Cyrus IMAP server, leading to denial of service or potentially the execution of arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name. For the stable distribution (stretch), this problem has been fixed in version 2.5.10-3+deb9u1. We recommend that you upgrade your cyrus-imapd packages. For the detailed security status of cyrus-imapd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/cyrus-imapd

Debian Security Advisory

DSA-4458-1 cyrus-imapd -- security update

Date Reported:
08 Jun 2019
Affected Packages:
cyrus-imapd
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2019-11356.
More information:

A flaw was discovered in the CalDAV feature in httpd of the Cyrus IMAP server, leading to denial of service or potentially the execution of arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

For the stable distribution (stretch), this problem has been fixed in version 2.5.10-3+deb9u1.

We recommend that you upgrade your cyrus-imapd packages.

For the detailed security status of cyrus-imapd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/cyrus-imapd