VDB
CVE-2024-34055
CVE-2024-34055
PUBLISHED
Es besteht eine Schwachstelle in cyrus imapd. Dieser Fehler besteht aufgrund einer unbegrenzten Speicherzuweisung. Durch das Senden vieler LITERALs in einem einzigen Befehl kann ein entfernter authentifizierter Angreifer diese Schwachstelle ausnutzen, um einen Denial-of-Service-Zustand zu verursachen.
EPSS 0.29% · 52.4th percentile
Risk Scores
EPSS Score
0.29%
52.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux | |
| Debian | Debian Linux | |
| Fedora | Fedora Linux | |
| Oracle | Oracle Linux | |
| Open Source | Open Source cyrus imapd <3.10.0-rc1 | |
| Ubuntu | Ubuntu Linux |
Exploit Intelligence
- CIRCL seen: CVE-2024-34055 (circl-sighting)
- CIRCL seen: CVE-2024-34055 (circl-sighting)
- CIRCL seen: CVE-2024-34055 (circl-sighting)
- https://github.com/cyrusimap/cyrus-imapd/commit/ef9e4e8314d6a06f2269af0ccf606894cc3fe489 (circl)
- https://www.cyrusimap.org/imap/download/release-notes/3.8/x/3.8.3.html (circl)
- https://www.cyrusimap.org/dev/imap/download/release-notes/3.10/x/3.10.0-rc1.html (circl)
- FEDORA-2024-f3e0255c75 (circl)
- FEDORA-2024-123f2b3666 (circl)
Timeline
- Jun 4, 2024 CVE Published
- Jun 14, 2024 EPSS Score
- Jul 7, 2024 EPSS Score
- Jul 30, 2024 EPSS Score
- Aug 22, 2024 EPSS Score
- Sep 14, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 6, 2024 EPSS Score
- Oct 29, 2024 EPSS Score
- Nov 21, 2024 EPSS Score
- Jan 7, 2025 EPSS Score
- Jan 23, 2025 CVE Updated
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1291.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1291 advisory
- https://www.cyrusimap.org/dev/imap/download/release-notes/3.10/x/3.10.0-rc1.html advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-34055 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2290510 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-123f2b3666 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-f3e0255c75 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-cfbdc342a2 advisory
- https://lists.debian.org/debian-security-announce/2024/msg00118.html advisory
- https://access.redhat.com/errata/RHSA-2024:9195 advisory
- https://linux.oracle.com/errata/ELSA-2024-9195.html advisory
- https://ubuntu.com/security/notices/USN-7224-1 advisory