CVE-2011-3208

NONE EPSS 91.7%
Published Sep 14, 201114y ago · Modified Jun 16, 20262w ago
Find Similar
Published Sep 14, 2011 14y ago
Last Modified Jun 16, 2026 2w ago

Description

Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.

Threat Intelligence

EPSS Exploit Probability
91.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer Memory Safety

Affected Products 40

VendorProductVersionRange
cmucyrus_imap_server* ≤2.3.16
cmucyrus_imap_server2.0.17any
cmucyrus_imap_server2.1.16any
cmucyrus_imap_server2.1.17any
cmucyrus_imap_server2.1.18any
cmucyrus_imap_server2.2.8any
cmucyrus_imap_server2.2.9any
cmucyrus_imap_server2.2.10any
cmucyrus_imap_server2.2.11any
cmucyrus_imap_server2.2.12any
cmucyrus_imap_server2.2.13any
cmucyrus_imap_server2.2.13p1any
cmucyrus_imap_server2.2.14any
cmucyrus_imap_server2.3.0any
cmucyrus_imap_server2.3.1any
cmucyrus_imap_server2.3.2any
cmucyrus_imap_server2.3.3any
cmucyrus_imap_server2.3.4any
cmucyrus_imap_server2.3.5any
cmucyrus_imap_server2.3.6any
cmucyrus_imap_server2.3.7any
cmucyrus_imap_server2.3.8any
cmucyrus_imap_server2.3.9any
cmucyrus_imap_server2.3.10any
cmucyrus_imap_server2.3.11any
cmucyrus_imap_server2.3.12any
cmucyrus_imap_server2.3.13any
cmucyrus_imap_server2.3.14any
cmucyrus_imap_server2.3.15any
cmucyrus_imap_server2.4.0any
cmucyrus_imap_server2.4.1any
cmucyrus_imap_server2.4.2any
cmucyrus_imap_server2.4.3any
cmucyrus_imap_server2.4.4any
cmucyrus_imap_server2.4.5any
cmucyrus_imap_server2.4.6any
cmucyrus_imap_server2.4.7any
cmucyrus_imap_server2.4.8any
cmucyrus_imap_server2.4.9any
cmucyrus_imap_server2.4.10any

References 17

Remediation

  • git.cyrusimap.org http://git.cyrusimap.org/cyrus-imapd/commit/?id=0f8f026699829b65733c3081657b24e2174f4f4d
    Patch
  • git.cyrusimap.org http://git.cyrusimap.org/cyrus-imapd/commit/?id=3244c18c928fa331f6927e2b8146abe90feafddd
    Patch
  • bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=734926
    Patch