Description
Cyrus 2.0.15, 2.0.16, and 1.6.24 on BSDi 4.2, with IMAP enabled, allows remote attackers to cause a denial of service (hang) using PHP IMAP clients.
Affected products
- bsdi / bsd_os4.2 – 4.2
- carnegie_mellon_university / cyrus_imap_server1.6.24 – 1.6.24
- carnegie_mellon_university / cyrus_imap_server2.0.15 – 2.0.15
- carnegie_mellon_university / cyrus_imap_server2.0.16 – 2.0.16