7.5
CVSSv2

CVE-2019-11356

Published: 03/06/2019 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The CalDAV feature in httpd in Cyrus IMAP 2.5.x up to and including 2.5.12 and 3.0.x up to and including 3.0.9 allows remote malicious users to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cyrus imap

fedoraproject fedora 29

fedoraproject fedora 30

debian debian linux 9.0

canonical ubuntu linux 18.04

redhat enterprise linux 8.0

redhat enterprise linux eus 8.1

redhat enterprise linux eus 8.2

redhat enterprise linux server tus 8.2

redhat enterprise linux server aus 8.2

redhat enterprise linux server tus 8.4

redhat enterprise linux eus 8.4

redhat enterprise linux server aus 8.4

Vendor Advisories

Synopsis Important: cyrus-imapd security update Type/Severity Security Advisory: Important Topic An update for cyrus-imapd is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) bas ...
A flaw was discovered in the CalDAV feature in httpd of the Cyrus IMAP server, leading to denial of service or potentially the execution of arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name For the stable distribution (stretch), this problem has been fixed in version 2510-3+deb9u1 We recommend that ...
Impact: Important Public Date: 2019-06-04 CWE: CWE-119 Bugzilla: 1717828: CVE-2019-11356 cyrus-imapd: s ...