FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2002-1580

This CVE name corresponds to:

Entered Topic
2004-05-12 Cyrus IMAP pre-authentication heap overflow vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2002-1580
Phase Assigned(20040513)

Description

Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length value that facilitates a buffer overflow attack, a different vulnerability than CVE-2002-1347.

References

Source Reference
BUGTRAQ 20021202 pre-login buffer overflow in Cyrus IMAP server
CONECTIVA CLA-2002:557
CONECTIVA 000557
DEBIAN DSA-215
CERT-VN VU#740169
CONFIRM http://asg.web.cmu.edu/cyrus/download/imapd/changes.html
XF cyrus-imap-preauth-bo(10744)
BID 6298