Vulnerability CVE-2021-33582: Information

Description

Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: Sept. 1, 2021
Modified: Nov. 7, 2023
Error type identifier: CWE-407

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
cyrus-imapdsisyphus3.2.8-alt13.4.6-alt2ALT-PU-2021-2724-1284607Fixed
cyrus-imapdp103.2.8-alt13.4.6-alt2ALT-PU-2021-2731-1284608Fixed
cyrus-imapdp93.2.8-alt13.2.8-alt1ALT-PU-2021-2758-1284606Fixed
cyrus-imapdp82.5.17-alt0.M80P.22.5.17-alt0.M80P.2ALT-PU-2021-2790-1284610Fixed
cyrus-imapdc10f13.2.8-alt13.2.8-alt1ALT-PU-2021-2731-1284608Fixed
cyrus-imapdp113.2.8-alt13.4.6-alt2ALT-PU-2021-2724-1284607Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
      End excliding
      3.0.16

      cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
      Start including
      3.2.0
      End excliding
      3.2.8

      cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
      Start including
      3.4.0
      End excliding
      3.4.2

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*