debian · CVE-2004-1013

Quick triage

Priority: not yet assigned 公開: Updated: Tue, 21 Jul 2026 13:05:04 GMT

檢視: Official debian advisory, NVD, CVE.org · CVE 詳情

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2004-1013 not yet assigned priority: Debian including 1 source packages (cyrus-imapd), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5.

Description:

The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p", or (3) "binary[p") that cause an index increment error that leads to an out-of-bounds memory corruption.

cvelogic Threat Intelligence