Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3052-1 | cyrus-imapd security update |
EUVD |
EUVD-2019-8601 | Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection. |
Ubuntu USN |
USN-7224-1 | Cyrus IMAP Server vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:02:39.852Z
Reserved: 2019-11-12T00:00:00
Link: CVE-2019-18928
No data.
Status : Modified
Published: 2019-11-15T04:15:10.267
Modified: 2024-11-21T04:33:51.193
Link: CVE-2019-18928
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN