7.5
CVSSv2

CVE-2015-8077

Published: 03/12/2015 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote malicious users to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.

Vulnerable Product Search on Vulmon Subscribe to Product

cyrus imap 2.4.4

cyrus imap 2.3.7

cyrus imap 2.4.6

cyrus imap 2.3.4

cyrus imap 2.4.16

cyrus imap 2.4.1

cyrus imap 2.3.5

cyrus imap 2.3.17

cyrus imap 2.4.0

cyrus imap 2.4.11

cyrus imap 2.5.1

cyrus imap 2.4.8

cyrus imap 2.4.10

cyrus imap 2.3.3

cyrus imap 2.3.8

cyrus imap 2.4.2

cyrus imap 2.5.0

cyrus imap 2.4.14

cyrus imap 2.3.14

cyrus imap 2.3.1

cyrus imap 2.4.17

cyrus imap 2.3.13

cyrus imap 2.3.10

cyrus imap 2.3.12

cyrus imap 2.3.9

cyrus imap 2.3.18

cyrus imap 2.4.3

cyrus imap 2.4.5

cyrus imap 2.4.7

cyrus imap 2.5.2

cyrus imap 2.3.16

cyrus imap 2.4.9

cyrus imap 2.3.6

cyrus imap 2.4.13

cyrus imap 2.4.12

cyrus imap 2.5.3

cyrus imap 2.3.11

cyrus imap 2.4.15

cyrus imap 2.3.15

cyrus imap 2.3.0

cyrus imap 2.3.2

opensuse leap 42.1

opensuse opensuse 13.2

Vendor Advisories

Debian Bug report logs - #804182 cyrus-imapd-24: CVE-2015-8077 CVE-2015-8078 Package: src:cyrus-imapd-24; Maintainer for src:cyrus-imapd-24 is Debian Cyrus Team <pkg-cyrus-imapd-debian-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 5 Nov 2015 20:15:01 UTC Severity ...
Integer overflow in the index_urlfetch function in imap/indexc in Cyrus IMAP 2319, 2418, and 256 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076 ...