7.5
CVSSv2

CVE-2015-8076

Published: 03/12/2015 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x prior to 2.3.19, 2.4.x prior to 2.4.18, 2.5.x prior to 2.5.4 allows remote malicious users to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.2

opensuse leap 42.1

cyrus imap 2.3.0

cyrus imap 2.3.1

cyrus imap 2.3.8

cyrus imap 2.3.9

cyrus imap 2.3.16

cyrus imap 2.3.17

cyrus imap 2.4.6

cyrus imap 2.4.7

cyrus imap 2.4.14

cyrus imap 2.4.15

cyrus imap 2.3.6

cyrus imap 2.3.7

cyrus imap 2.3.14

cyrus imap 2.3.15

cyrus imap 2.4.4

cyrus imap 2.4.5

cyrus imap 2.4.12

cyrus imap 2.4.13

cyrus imap 2.5.2

cyrus imap 2.5.3

cyrus imap 2.3.4

cyrus imap 2.3.5

cyrus imap 2.3.12

cyrus imap 2.3.13

cyrus imap 2.4.1

cyrus imap 2.4.2

cyrus imap 2.4.3

cyrus imap 2.4.10

cyrus imap 2.4.11

cyrus imap 2.5.0

cyrus imap 2.5.1

cyrus imap 2.3.2

cyrus imap 2.3.3

cyrus imap 2.3.10

cyrus imap 2.3.11

cyrus imap 2.3.18

cyrus imap 2.4.0

cyrus imap 2.4.8

cyrus imap 2.4.9

cyrus imap 2.4.16

cyrus imap 2.4.17

Vendor Advisories

Debian Bug report logs - #804182 cyrus-imapd-24: CVE-2015-8077 CVE-2015-8078 Package: src:cyrus-imapd-24; Maintainer for src:cyrus-imapd-24 is Debian Cyrus Team <pkg-cyrus-imapd-debian-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 5 Nov 2015 20:15:01 UTC Severity ...
The index_urlfetch function in indexc in Cyrus IMAP 23x before 2319, 24x before 2418, 25x before 254 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read ...