Bugzilla – Bug 1225990
VUL-0: CVE-2024-34055: cyrus-imapd: unbounded memory allocation by sending many LITERALs in a single command
Last modified: 2024-06-07 16:24:48 UTC
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-34055 https://www.cve.org/CVERecord?id=CVE-2024-34055 https://github.com/cyrusimap/cyrus-imapd/commit/ef9e4e8314d6a06f2269af0ccf606894cc3fe489 https://www.cyrusimap.org/dev/imap/download/release-notes/3.10/x/3.10.0-rc1.html https://www.cyrusimap.org/imap/download/release-notes/3.8/x/3.8.3.html https://bugzilla.redhat.com/show_bug.cgi?id=2290510
I already updated my packages to versions 3.4.8, 3.6.5, 3.8.3 and 3.10.0-rc1 that contain a fix for CVE-2024-34055.