VYPR
Critical severity9.8NVD Advisory· Published Jun 3, 2019· Updated Jun 17, 2026

CVE-2019-11356

CVE-2019-11356

Description

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

16
  • Cyrus/IMAP2 versions
    cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*range: >=2.5.0,<=2.5.12
    • (no CPE)range: 2.5.x through 2.5.12, 3.0.x through 3.0.9
  • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*
  • Cyrus/IMAPdescription

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.