[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#993492: buster-pu: package cyrus-imapd/3.0.8-6+deb10u6



Control: tags -1 + confirmed

On Thu, 2021-09-02 at 08:00 +0200, Yadd wrote:
> cyrus-imapd before 3.0.16 allows remote attackers to cause a denial
> of
> service (multiple-minute daemon hang) via input that is mishandled
> during hash-table interaction. Because there are many insertions into
> a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8,
> and 3.0.16.
> 

Please go ahead.

Regards,

Adam


Reply to: