Cyrus IMAP Server: Access restriction bypass An error in Cyrus IMAP Server allows mailboxes to be created with administrative privileges. cyrusimap 2020-06-15 2020-06-15 703630 remote 3.0.13 3.0.13

The Cyrus IMAP Server is an efficient, highly-scalable IMAP e-mail server.

An issue was discovered in Cyrus IMAP Server where sieve script uploading is excessively trusted.

A user can use a sieve script to create any mailbox with administrator privileges.

Disable sieve script uploading until the upgrade is complete.

All Cyrus IMAP Server users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-mail/cyrus-imapd-3.0.13"
CVE-2019-19783 sam_c sam_c