ALT-PU-2015-1613-1
Package cyrus-imapd updated to version 2.4.18-alt0.M70P.1 for branch t7 in task 146386.
Closed vulnerabilities
BDU:2016-00362
Уязвимость почтового сервера Cyrus IMAP и операционных систем openSUSE и OpenSUSE Leap, позволяющая нарушителю получить конфиденциальную информацию или оказать другое воздействие
BDU:2016-00363
Уязвимость почтового сервера Cyrus IMAP и операционных систем openSUSE и OpenSUSE Leap, позволяющая нарушителю нарушить целостность и доступность защищаемой информации
BDU:2016-00364
Уязвимость почтового сервера Cyrus IMAP и операционных систем openSUSE и OpenSUSE Leap, позволяющая нарушителю нарушить целостность и доступность защищаемой информации
Modified: 2024-11-21
CVE-2015-8076
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.
- SUSE-SU-2016:1457
- SUSE-SU-2016:1457
- SUSE-SU-2016:1459
- SUSE-SU-2016:1459
- openSUSE-SU-2015:1622
- openSUSE-SU-2015:1622
- openSUSE-SU-2015:1623
- openSUSE-SU-2015:1623
- [oss-security] 20150929 CVE request: urlfetch range handling flaw in Cyrus
- [oss-security] 20150929 CVE request: urlfetch range handling flaw in Cyrus
- [oss-security] 20150930 Re: CVE request: urlfetch range handling flaw in Cyrus IMAP
- [oss-security] 20150930 Re: CVE request: urlfetch range handling flaw in Cyrus IMAP
- [oss-security] 20151104 Re: CVE request: urlfetch range handling flaw in Cyrus IMAP
- [oss-security] 20151104 Re: CVE request: urlfetch range handling flaw in Cyrus IMAP
- https://cyrus.foundation/cyrus-imapd/commit/?id=07de4ff1bf2fa340b9d77b8e7de8d43d47a33921
- https://cyrus.foundation/cyrus-imapd/commit/?id=07de4ff1bf2fa340b9d77b8e7de8d43d47a33921
- https://cyrus.foundation/cyrus-imapd/commit/?id=c21e179c1f6b968fe69bebe079176714e511587b
- https://cyrus.foundation/cyrus-imapd/commit/?id=c21e179c1f6b968fe69bebe079176714e511587b
- https://docs.cyrus.foundation/imap/release-notes/2.3/x/2.3.19.html
- https://docs.cyrus.foundation/imap/release-notes/2.3/x/2.3.19.html
- https://docs.cyrus.foundation/imap/release-notes/2.4/x/2.4.18.html
- https://docs.cyrus.foundation/imap/release-notes/2.4/x/2.4.18.html
- https://docs.cyrus.foundation/imap/release-notes/2.5/x/2.5.4.html
- https://docs.cyrus.foundation/imap/release-notes/2.5/x/2.5.4.html
Modified: 2024-11-21
CVE-2015-8077
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
- SUSE-SU-2016:1457
- SUSE-SU-2016:1457
- SUSE-SU-2016:1459
- SUSE-SU-2016:1459
- openSUSE-SU-2015:2130
- openSUSE-SU-2015:2130
- openSUSE-SU-2015:2200
- openSUSE-SU-2015:2200
- [oss-security] 20150930 Re: CVE request: urlfetch range handling flaw in Cyrus IMAP
- [oss-security] 20150930 Re: CVE request: urlfetch range handling flaw in Cyrus IMAP
- [oss-security] 20151104 Re: CVE request: urlfetch range handling flaw in Cyrus IMAP
- [oss-security] 20151104 Re: CVE request: urlfetch range handling flaw in Cyrus IMAP
- 1034282
- 1034282
- https://cyrus.foundation/cyrus-imapd/commit/?id=745e161c834f1eb6d62fc14477f51dae799e1e08
- https://cyrus.foundation/cyrus-imapd/commit/?id=745e161c834f1eb6d62fc14477f51dae799e1e08
- https://docs.cyrus.foundation/imap/release-notes/2.5/x/2.5.7.html
- https://docs.cyrus.foundation/imap/release-notes/2.5/x/2.5.7.html
- [Cyrus-devel] 20151005 Recent security fixes
- [Cyrus-devel] 20151005 Recent security fixes
Modified: 2024-11-21
CVE-2015-8078
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
- SUSE-SU-2016:1457
- SUSE-SU-2016:1457
- SUSE-SU-2016:1459
- SUSE-SU-2016:1459
- openSUSE-SU-2015:2130
- openSUSE-SU-2015:2130
- [oss-security] 20151104 Re: CVE request: urlfetch range handling flaw in Cyrus IMAP
- [oss-security] 20151104 Re: CVE request: urlfetch range handling flaw in Cyrus IMAP
- 1034282
- 1034282
- https://cyrus.foundation/cyrus-imapd/commit/?id=6fb6a272171f49c79ba6ab7c6403eb25b39ec1b2
- https://cyrus.foundation/cyrus-imapd/commit/?id=6fb6a272171f49c79ba6ab7c6403eb25b39ec1b2
- https://docs.cyrus.foundation/imap/release-notes/2.5/x/2.5.7.html
- https://docs.cyrus.foundation/imap/release-notes/2.5/x/2.5.7.html
Closed bugs
стартовый скрипт cyrus-imap всегда перезаписывает ключи SSL