Bugzilla – Bug 954201
VUL-0: CVE-2015-8078: cyrus-imapd: Integer overflow in index_urlfetch
Last modified: 2016-08-01 09:04:24 UTC
Quoting from RH BZ: "An integer overflow vulnerability that emerged after applying partial fix for CVE-2015-8076 by commit https://cyrus.foundation/cyrus-imapd/commit/?id=c21e179c1f6b968fe69bebe079176714e511587b was found." patch: https://cyrus.foundation/cyrus-imapd/commit/?id=6fb6a272171f49c79ba6ab7c6403eb25b39ec1b2 References: https://bugzilla.redhat.com/show_bug.cgi?id=1278380 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8078 http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-8078.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8078
bugbot adjusting priority
Created SR#344607 for openSUSE_13.2 and openSUSE_Leap_42.1 (both containing patches for cyrus-imapd 2.4). Created SR#344608 for openSUSE_Tumleweed (containing cyrus-imapd 2.4) Does this issue also affect cyrus-imapd 2.3?
This is an autogenerated message for OBS integration: This bug (954201) was mentioned in https://build.opensuse.org/request/show/344607 13.2+Leap:42.1 / cyrus-imapd.openSUSE_Leap_42.1_Update+cyrus-imapd_13.2
(In reply to Aeneas Jaißle from comment #2) Looks like it. The the check that was fixed here was introduced by commit c21e179c1f6b968fe69bebe079176714e511587b Author: ellie timoney Date: Fri Jun 26 11:24:38 2015 +1000 urlfetch: extra paranoia Before this "extra paranoia" there was no check at all, so we probably should include it.
openSUSE-SU-2015:2130-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 954200,954201 CVE References: CVE-2015-8077,CVE-2015-8078 Sources used: openSUSE Leap 42.1 (src): cyrus-imapd-2.4.18-3.1 openSUSE 13.2 (src): cyrus-imapd-2.4.18-2.10.1
affectes sle10, sle11 and sle12 too.
An update workflow for this issue was started. This issue was rated as important. Please submit fixed packages until 2016-06-06. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/62790
SUSE-SU-2016:1457-1: An update that solves four vulnerabilities and has one errata is now available. Category: security (important) Bug References: 860611,901748,954200,954201,981670 CVE References: CVE-2014-3566,CVE-2015-8076,CVE-2015-8077,CVE-2015-8078 Sources used: SUSE Linux Enterprise Server 12-SP1 (src): cyrus-imapd-2.3.18-37.1 SUSE Linux Enterprise Server 12 (src): cyrus-imapd-2.3.18-37.1
SUSE-SU-2016:1459-1: An update that solves four vulnerabilities and has one errata is now available. Category: security (important) Bug References: 860611,901748,954200,954201,981670 CVE References: CVE-2014-3566,CVE-2015-8076,CVE-2015-8077,CVE-2015-8078 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): cyrus-imapd-2.3.11-60.65.67.1 SUSE Linux Enterprise Server 11-SP4 (src): cyrus-imapd-2.3.11-60.65.67.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): cyrus-imapd-2.3.11-60.65.67.1
released