CVE-2004-1067

Publication date 10 January 2005

Last updated 17 July 2025


Ubuntu priority

Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username.

Status

Package Ubuntu Release Status
cyrus21-imapd 7.04 feisty
Fixed 2.1.18-2ubuntu2
6.10 edgy
Fixed 2.1.18-2ubuntu2
6.06 LTS dapper
Fixed 2.1.18-2ubuntu2

References

Related Ubuntu Security Notices (USN)

    • USN-37-1
    • cyrus21-imapd vulnerability
    • 2 December 2004

Other references