Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.56502
Category:Fedora Local Security Checks
Title:Fedora Legacy Security Advisory FLSA-2006:156290
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory FLSA-2006:156290.

Several buffer overflow bugs were found in cyrus-imapd. It is possible
that an authenticated malicious user could cause the imap server to
crash. Additionally, a peer news admin could potentially execute
arbitrary code on the imap server when news is received using the
fetchnews command. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-2005-0546 to this issue.

Users of cyrus-imapd are advised to upgrade to these updated packages,
which contain cyrus-imapd version 2.2.12 to correct these issues.

Affected platforms:
Fedora Core 2

Solution:
https://secure1.securityspace.com/smysecure/catid.html?in=FLSA-2006:156290

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-0546
BugTraq ID: 12636
http://www.securityfocus.com/bid/12636
Bugtraq: 20050228 [USN-87-1] Cyrus IMAP server vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=110972236203397&w=2
Conectiva Linux advisory: CLA-2005:937
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000937
http://www.securityfocus.com/archive/1/430294/100/0/threaded
http://security.gentoo.org/glsa/glsa-200502-29.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2005:051
http://asg.web.cmu.edu/archive/message.php?mailbox=archive.info-cyrus&msg=33723
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10674
http://www.redhat.com/support/errata/RHSA-2005-408.html
http://securitytracker.com/id?1013278
http://secunia.com/advisories/14383
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.