Vulnerability Name: | CVE-2017-12843 (CCN-130855) | ||||||||||||||||
Assigned: | 2017-08-14 | ||||||||||||||||
Published: | 2017-08-14 | ||||||||||||||||
Updated: | 2017-08-26 | ||||||||||||||||
Summary: | Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command. | ||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
| ||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-12843 Source: XF Type: UNKNOWN cyrus-imap-cve201712843-file-overwrite(130855) Source: CONFIRM Type: Third Party Advisory https://github.com/cyrusimap/cyrus-imapd/commit/53c4137bd924b954432c6c59da7572c4c5ffa901 Source: CONFIRM Type: Third Party Advisory https://github.com/cyrusimap/cyrus-imapd/commit/5edadcfb83bf27107578830801817f9e6d0ad941 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2017-f8f4cd5b67 Source: CCN Type: Cyrus IMAP Web site Cyrus IMAP 3.0.3 Release Notes Source: CONFIRM Type: Release Notes, Vendor Advisory https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.3.html Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-12843 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |