Bug 1225990 (CVE-2024-34055)

Summary: VUL-0: CVE-2024-34055: cyrus-imapd: unbounded memory allocation by sending many LITERALs in a single command
Product: [openSUSE] openSUSE Distribution Reporter: SMASH SMASH <smash_bz>
Component: SecurityAssignee: Matthias Fehring <buschmann23>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: andrea.mattiazzo
Version: Leap 15.6   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/408761/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Comment 1 Matthias Fehring 2024-06-07 16:24:48 UTC
I already updated my packages to versions 3.4.8, 3.6.5, 3.8.3 and 3.10.0-rc1 that contain a fix for CVE-2024-34055.