CVE-2011-3372
Publication date 24 December 2011
Last updated 24 July 2024
Ubuntu priority
Description
imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| cyrus-imapd-2.2 | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
| cyrus-imapd-2.4 | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |
| kolab-cyrus-imapd | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
Patch details
| Package | Patch details |
|---|---|
| cyrus-imapd-2.2 |