7.5
CVSSv2

CVE-2015-8078

Published: 03/12/2015 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote malicious users to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse leap 42.1

opensuse opensuse 13.2

cyrus imap 2.4.4

cyrus imap 2.3.7

cyrus imap 2.4.6

cyrus imap 2.3.4

cyrus imap 2.4.16

cyrus imap 2.4.1

cyrus imap 2.3.5

cyrus imap 2.3.17

cyrus imap 2.4.0

cyrus imap 2.4.11

cyrus imap 2.5.1

cyrus imap 2.4.8

cyrus imap 2.4.10

cyrus imap 2.3.3

cyrus imap 2.3.8

cyrus imap 2.4.2

cyrus imap 2.5.0

cyrus imap 2.4.14

cyrus imap 2.3.14

cyrus imap 2.3.1

cyrus imap 2.4.17

cyrus imap 2.3.13

cyrus imap 2.3.10

cyrus imap 2.3.12

cyrus imap 2.3.9

cyrus imap 2.3.18

cyrus imap 2.4.3

cyrus imap 2.4.5

cyrus imap 2.4.7

cyrus imap 2.5.2

cyrus imap 2.3.16

cyrus imap 2.4.9

cyrus imap 2.3.6

cyrus imap 2.4.13

cyrus imap 2.4.12

cyrus imap 2.5.3

cyrus imap 2.3.11

cyrus imap 2.4.15

cyrus imap 2.3.15

cyrus imap 2.3.0

cyrus imap 2.3.2

Vendor Advisories

Debian Bug report logs - #804182 cyrus-imapd-24: CVE-2015-8077 CVE-2015-8078 Package: src:cyrus-imapd-24; Maintainer for src:cyrus-imapd-24 is Debian Cyrus Team <pkg-cyrus-imapd-debian-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 5 Nov 2015 20:15:01 UTC Severity ...
Integer overflow in the index_urlfetch function in imap/indexc in Cyrus IMAP 2319, 2418, and 256 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076 ...