IMAP: Cyrus IMAP Server Pre-Login Buffer Overflow

This signature detects attempts to exploit a known vulnerability against Cyrus IMAPd. Cyrus IMAPd versions 1.4 through 2.1.10 are vulnerable. A successful attack can allow the attacker to overflow the buffer prior to authentication, permitting arbitrary code execution and compromising the system.

Extended Description

A memory corruption vulnerability has been discovered in SASL when generating logs files. It has been reported that under some circumstances SASL fails to allocate sufficient memory for string used in log entries. By causing Cyrus to generate a malicious log it may be possible for an attacker to corrupt memory. This could potentially be exploited to overwrite the LSB of a sensitive variable or possibly cause inaccurate logs to be created. It should be noted that although this vulnerability was discovered in Cyrus, it may also affect other programs that utilize the SASL library.

Affected Products

Apple mac_os_x

Short Name
IMAP:CYRUS:PRELOG
Severity
Major
Recommended
False
Recommended Action
Drop
Category
IMAP
Keywords
Buffer CVE-2002-1347 Cyrus IMAP Overflow Pre-Login Server bid:6349
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Apple

Cyrus-utils

CVSS Score

7.5

Found a potential security threat?