Vulnerability Name:

CVE-2017-14230 (CCN-131946)

Assigned:2017-09-10
Published:2017-09-10
Updated:2017-09-21
Summary:In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain sensitive information or cause a denial of service (daemon crash) via a 'LIST "" "Other Users"' command.
CVSS v3 Severity:9.1 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
7.9 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): High
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): Partial
6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-20
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2017-14230

Source: XF
Type: UNKNOWN
cyrusimap-cve201714230-info-disc(131946)

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
https://github.com/cyrusimap/cyrus-imapd/commit/6bd33275368edfa71ae117de895488584678ac79

Source: CCN
Type: cyrus-imapd GIT Repository
Broken `Other Users` behaviour in 3.0.2 #2132

Source: CONFIRM
Type: Issue Tracking, Third Party Advisory
https://github.com/cyrusimap/cyrus-imapd/issues/2132

Source: CONFIRM
Type: Third Party Advisory
https://lists.andrew.cmu.edu/pipermail/cyrus-announce/2017-September/000145.html

Source: CONFIRM
Type: Release Notes, Third Party Advisory
https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.4.html

Vulnerable Configuration:Configuration 1:
  • cpe:/a:cyrus:imap:*:*:*:*:*:*:*:* (Version <= 3.0.3)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201714230
    V
    CVE-2017-14230
    2022-05-20
    oval:org.opensuse.security:def:30169
    P
    Security update for MozillaFirefox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:33757
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:34003
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:33041
    P
    Security update for qemu (Important)
    2021-11-10
    oval:org.opensuse.security:def:33718
    P
    Security update for gtk-vnc (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:30125
    P
    Security update for transfig (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:32997
    P
    Security update for xen (Important)
    2021-09-06
    oval:org.opensuse.security:def:33700
    P
    Security update for fetchmail (Moderate)
    2021-08-18
    oval:org.opensuse.security:def:32974
    P
    Security update for djvulibre (Important)
    2021-08-05
    oval:org.opensuse.security:def:30106
    P
    Security update for linuxptp (Important)
    2021-07-21
    oval:org.opensuse.security:def:33679
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:32935
    P
    Security update for gstreamer-plugins-bad (Important)
    2021-06-07
    oval:org.opensuse.security:def:30067
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:28948
    P
    Security update for the Linux Kernel (Important)
    2021-03-09
    oval:org.opensuse.security:def:28931
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:30018
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:29963
    P
    Security update for xen (Moderate)
    2020-12-22
    oval:org.opensuse.security:def:32829
    P
    Security update for openssl (Important)
    2020-12-11
    oval:org.opensuse.security:def:28637
    P
    Security update for bind
    2020-12-01
    oval:org.opensuse.security:def:29666
    P
    Security update for cyrus-imapd (Low)
    2020-12-01
    oval:org.opensuse.security:def:29667
    P
    Security update for dbus-1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34061
    P
    Security update for libxml2
    2020-12-01
    oval:org.opensuse.security:def:28789
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29724
    P
    Security update for MozillaFirefox, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:30807
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:32435
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:34110
    P
    Security update for mutt (Important)
    2020-12-01
    oval:org.opensuse.security:def:28843
    P
    Security update for wget
    2020-12-01
    oval:org.opensuse.security:def:29810
    P
    Security update for jakarta
    2020-12-01
    oval:org.opensuse.security:def:30844
    P
    Security update for cyrus-imapd (Low)
    2020-12-01
    oval:org.opensuse.security:def:32529
    P
    gzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28411
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34149
    P
    Security update for openssh
    2020-12-01
    oval:org.opensuse.security:def:28892
    P
    Security update for ecryptfs-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32586
    P
    openswan on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33604
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34174
    P
    Security update for openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32673
    P
    glibc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34218
    P
    Security update for php5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29580
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34856
    P
    Security update for cifs-utils (Important)
    2020-12-01
    oval:org.opensuse.security:def:28496
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:28992
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32886
    P
    java-1_6_0-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33846
    P
    Security update for guile (Low)
    2020-12-01
    oval:org.opensuse.security:def:34896
    P
    Security update for cyrus-imapd (Low)
    2020-12-01
    oval:org.opensuse.security:def:28553
    P
    Security update for flash-player
    2020-12-01
    oval:org.opensuse.security:def:29630
    P
    Security update for clamav (Important)
    2020-12-01
    oval:com.ubuntu.xenial:def:2017142300000000
    V
    CVE-2017-14230 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-09-10
    oval:com.ubuntu.artful:def:201714230000
    V
    CVE-2017-14230 on Ubuntu 17.10 (artful) - medium.
    2017-09-10
    oval:com.ubuntu.xenial:def:201714230000
    V
    CVE-2017-14230 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-09-10
    oval:com.ubuntu.bionic:def:201714230000
    V
    CVE-2017-14230 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-09-10
    oval:com.ubuntu.cosmic:def:2017142300000000
    V
    CVE-2017-14230 on Ubuntu 18.10 (cosmic) - medium.
    2017-09-10
    oval:com.ubuntu.cosmic:def:201714230000
    V
    CVE-2017-14230 on Ubuntu 18.10 (cosmic) - medium.
    2017-09-10
    oval:com.ubuntu.bionic:def:2017142300000000
    V
    CVE-2017-14230 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-09-10
    oval:com.ubuntu.trusty:def:201714230000
    V
    CVE-2017-14230 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-09-10
    BACK
    cyrus imap *