CVE-2011-3481 describes a denial-of-service vulnerability in Cyrus IMAP Server versions prior to 2.4.11, specifically within the imapd's index_get_ids function when server-side threading is enabled. A remote attacker can trigger a NULL pointer dereference and daemon crash by sending a specially crafted email with a malicious References header. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and partial availability impact, but no confidentiality or integrity impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.10CPE matchmatch criteria | cpe:2.3:a:cmu:cyrus_imap_server:*:*:*:*:*:*:*:* | ||
2.0.17CPE matchmatch criteria | cpe:2.3:a:cmu:cyrus_imap_server:2.0.17:*:*:*:*:*:*:* | ||
2.1.16CPE matchmatch criteria | cpe:2.3:a:cmu:cyrus_imap_server:2.1.16:*:*:*:*:*:*:* | ||
2.1.17CPE matchmatch criteria | cpe:2.3:a:cmu:cyrus_imap_server:2.1.17:*:*:*:*:*:*:* | ||
2.1.18CPE matchmatch criteria | cpe:2.3:a:cmu:cyrus_imap_server:2.1.18:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.