PublicDate: 2005-01-10 05:00:00 UTC Candidate: CVE-2004-1013 References: https://ubuntu.com/security/notices/USN-31-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1013 Description: The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p", or (3) "binary[p") that cause an index increment error that leads to an out-of-bounds memory corruption. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_cyrus21-imapd: released (2.1.18-2ubuntu2) edgy_cyrus21-imapd: released (2.1.18-2ubuntu2) feisty_cyrus21-imapd: released (2.1.18-2ubuntu2) devel_cyrus21-imapd: DNE upstream_cyrus21-imapd: needs-triage