Cyrus 2.0.15, 2.0.16, and 1.6.24 on BSDi 4.2, with IMAP enabled, allows remote attackers to cause a denial of service (hang) using PHP IMAP clients.
Software | From | Fixed in |
---|---|---|
bsdi / bsd_os | 4.2 | 4.2.x |
carnegie_mellon_university / cyrus_imap_server | 1.6.24 | 1.6.24.x |
carnegie_mellon_university / cyrus_imap_server | 2.0.15 | 2.0.15.x |
carnegie_mellon_university / cyrus_imap_server | 2.0.16 | 2.0.16.x |