Upstream information
Description
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body.peek") and causes an index increment error that leads to an out-of-bounds memory corruption.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having critical severity.
| CVSS detail | National Vulnerability Database | 
|---|---|
| Base Score | 10 | 
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C | 
| Access Vector | Network | 
| Access Complexity | Low | 
| Authentication | None | 
| Confidentiality Impact | Complete | 
| Integrity Impact | Complete | 
| Availability Impact | Complete | 
SUSE Security Advisories:
- SUSE-SA:2004:043, published Friday, Dec 3rd 2004 13:00 MEST
 - SUSE-SR:2004:003, published Tuesday, Dec 7th 2004 15:00 MEST
 
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 01:02:14 2013CVE page last modified: Mon Oct 6 18:14:36 2025