{ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2019-19783", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "url": "https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.15.html", "refsource": "MISC", "name": "https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.15.html" }, { "url": "https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.13.html", "refsource": "MISC", "name": "https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.13.html" }, { "refsource": "BUGTRAQ", "name": "20191219 [SECURITY] [DSA 4590-1] cyrus-imapd security update", "url": "https://seclists.org/bugtraq/2019/Dec/38" }, { "refsource": "DEBIAN", "name": "DSA-4590", "url": "https://www.debian.org/security/2019/dsa-4590" }, { "refsource": "FEDORA", "name": "FEDORA-2019-7938c21723", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2DIV4HQ6LG5GPRO4B5Z2NHCZUPBUVVVF/" }, { "refsource": "FEDORA", "name": "FEDORA-2019-ad23a4522d", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6IGOO5UGEBBDPN7B2YXLK7I7L3Y35EBA/" }, { "refsource": "GENTOO", "name": "GLSA-202006-23", "url": "https://security.gentoo.org/glsa/202006-23" }, { "refsource": "UBUNTU", "name": "USN-4566-1", "url": "https://usn.ubuntu.com/4566-1/" } ] } }