CVE-2011-3208
NONE EPSS 91.7%
Published Sep 14, 201114y ago · Modified Jun 16, 20262w ago
Published Sep 14, 2011 14y ago
Last Modified Jun 16, 2026 2w ago
Description
Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.
Threat Intelligence
EPSS Exploit Probability
91.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer Memory Safety
Affected Products 40
| Vendor | Product | Version | Range |
|---|---|---|---|
| cmu | cyrus_imap_server | * | ≤2.3.16 |
| cmu | cyrus_imap_server | 2.0.17 | any |
| cmu | cyrus_imap_server | 2.1.16 | any |
| cmu | cyrus_imap_server | 2.1.17 | any |
| cmu | cyrus_imap_server | 2.1.18 | any |
| cmu | cyrus_imap_server | 2.2.8 | any |
| cmu | cyrus_imap_server | 2.2.9 | any |
| cmu | cyrus_imap_server | 2.2.10 | any |
| cmu | cyrus_imap_server | 2.2.11 | any |
| cmu | cyrus_imap_server | 2.2.12 | any |
| cmu | cyrus_imap_server | 2.2.13 | any |
| cmu | cyrus_imap_server | 2.2.13p1 | any |
| cmu | cyrus_imap_server | 2.2.14 | any |
| cmu | cyrus_imap_server | 2.3.0 | any |
| cmu | cyrus_imap_server | 2.3.1 | any |
| cmu | cyrus_imap_server | 2.3.2 | any |
| cmu | cyrus_imap_server | 2.3.3 | any |
| cmu | cyrus_imap_server | 2.3.4 | any |
| cmu | cyrus_imap_server | 2.3.5 | any |
| cmu | cyrus_imap_server | 2.3.6 | any |
| cmu | cyrus_imap_server | 2.3.7 | any |
| cmu | cyrus_imap_server | 2.3.8 | any |
| cmu | cyrus_imap_server | 2.3.9 | any |
| cmu | cyrus_imap_server | 2.3.10 | any |
| cmu | cyrus_imap_server | 2.3.11 | any |
| cmu | cyrus_imap_server | 2.3.12 | any |
| cmu | cyrus_imap_server | 2.3.13 | any |
| cmu | cyrus_imap_server | 2.3.14 | any |
| cmu | cyrus_imap_server | 2.3.15 | any |
| cmu | cyrus_imap_server | 2.4.0 | any |
| cmu | cyrus_imap_server | 2.4.1 | any |
| cmu | cyrus_imap_server | 2.4.2 | any |
| cmu | cyrus_imap_server | 2.4.3 | any |
| cmu | cyrus_imap_server | 2.4.4 | any |
| cmu | cyrus_imap_server | 2.4.5 | any |
| cmu | cyrus_imap_server | 2.4.6 | any |
| cmu | cyrus_imap_server | 2.4.7 | any |
| cmu | cyrus_imap_server | 2.4.8 | any |
| cmu | cyrus_imap_server | 2.4.9 | any |
| cmu | cyrus_imap_server | 2.4.10 | any |
References 17
- asg.andrew.cmu.edu http://asg.andrew.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&msg=199
- asg.andrew.cmu.edu http://asg.andrew.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&msg=200
- git.cyrusimap.org http://git.cyrusimap.org/cyrus-imapd/commit/?id=0f8f026699829b65733c3081657b24e2174f4f4d
- git.cyrusimap.org http://git.cyrusimap.org/cyrus-imapd/commit/?id=3244c18c928fa331f6927e2b8146abe90feafddd
- lists.opensuse.org http://lists.opensuse.org/opensuse-updates/2011-09/msg00019.html
- secunia.com http://secunia.com/advisories/45938
- secunia.com http://secunia.com/advisories/45975
- secunia.com http://secunia.com/advisories/46064
- securitytracker.com http://securitytracker.com/id?1026031
- debian.org http://www.debian.org/security/2011/dsa-2318
- mandriva.com http://www.mandriva.com/security/advisories?name=MDVSA-2011:149
- osvdb.org http://www.osvdb.org/75307
- redhat.com http://www.redhat.com/support/errata/RHSA-2011-1317.html
- securityfocus.com http://www.securityfocus.com/bid/49534
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=734926
- exchange.xforce.ibmcloud.com https://exchange.xforce.ibmcloud.com/vulnerabilities/69679
- hermes.opensuse.org https://hermes.opensuse.org/messages/11723935
Remediation
- git.cyrusimap.org http://git.cyrusimap.org/cyrus-imapd/commit/?id=0f8f026699829b65733c3081657b24e2174f4f4d
- git.cyrusimap.org http://git.cyrusimap.org/cyrus-imapd/commit/?id=3244c18c928fa331f6927e2b8146abe90feafddd
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=734926