[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#993489: bullseye-pu: package cyrus-imapd/3.2.6-2+deb11u1



Control: tags -1 + confirmed

On Thu, 2021-09-02 at 06:26 +0200, Yadd wrote:
> cyrus-imapd before 3.2.8 allows remote attackers to cause a denial of
> service (multiple-minute daemon hang) via input that is mishandled
> during hash-table interaction. Because there are many insertions into
> a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8,
> and 3.0.16.
> 

Please go ahead.

Regards,

Adam


Reply to: