Updated cyrus-imapd packages fix security vulnerability
Publication date: 05 Jul 2022Modification date: 05 Jul 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-33582
Description
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. (CVE-2021-33582)
References
SRPMS
8/core
- cyrus-imapd-2.5.15-3.1.mga8