========================================================================== Ubuntu Security Notice USN-4566-1 October 05, 2020 cyrus-imapd vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Cyrus IMAP Server could be made to overwrite files as the administrator. Software Description: - cyrus-imapd: An IMAP server Details: It was dicovered that Cyrus IMAP Server could execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name. An attacker could use this vulnerability to cause a crash or possibly execute arbitrary code. (CVE-2019-11356) It was discovered that the Cyrus IMAP Server allow users to create any mailbox with administrative privileges. A local attacker could use this to obtain sensitive information. (CVE-2019-19783) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: cyrus-admin 2.5.10-3ubuntu1.1 cyrus-caldav 2.5.10-3ubuntu1.1 cyrus-common 2.5.10-3ubuntu1.1 cyrus-imapd 2.5.10-3ubuntu1.1 cyrus-replication 2.5.10-3ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://usn.ubuntu.com/4566-1 CVE-2019-11356, CVE-2019-19783 Package Information: https://launchpad.net/ubuntu/+source/cyrus-imapd/2.5.10-3ubuntu1.1