PT-2019-5233 · Cyrus+4 · Cyrus Imap+4

CVE-2019-19783

·

Publicado

2019-12-16

·

Atualizado

2025-04-04

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cyrus IMAP versions prior to 2.5.15 Cyrus IMAP versions 3.0.x prior to 3.0.13 Cyrus IMAP versions 3.1.x through 3.1.8
Description The issue is related to a lack of input validation mechanism in the Cyrus IMAP server, which can be exploited by a remote attacker to impact the integrity of information. If sieve script uploading is allowed or certain non-default sieve options are enabled, a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges due to folder mishandling in the autosieve createfolder() function.
Recommendations For Cyrus IMAP versions prior to 2.5.15, update to version 2.5.15 or later. For Cyrus IMAP versions 3.0.x prior to 3.0.13, update to version 3.0.13 or later. For Cyrus IMAP versions 3.1.x through 3.1.8, update to a version later than 3.1.8. As a temporary workaround, consider disabling sieve script uploading or restricting the use of non-default sieve options until a patch is available.

Correção

Improper Privilege Management

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-1001
ALT-PU-2020-1020
BDU:2020-01976
CESA-2020_4655
CVE-2019-19783
DSA-4590-1
MGASA-2020-0010
OPENSUSE-SU-2025:14968-1
RHSA-2020:4655
RHSA-2020_4655
USN-4566-1

Produtos afetados

Alt Linux
Centos
Cyrus Imap
Red Hat
Ubuntu