Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
| Software | From | Fixed in |
|---|---|---|
| cyrusimap / cyrus_imap | 3.10.0-beta1 | 3.10.0-beta1.x |
| cyrusimap / cyrus_imap | 3.10.0-beta2 | 3.10.0-beta2.x |
| cyrusimap / cyrus_imap | 3.10.0-alpha0 | 3.10.0-alpha0.x |
| cyrusimap / cyrus_imap | - | 3.8.3 |