{"id":"CVE-2019-11356","details":"The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.","modified":"2026-04-16T04:33:58.061217245Z","published":"2019-06-03T20:29:00.297Z","related":["openSUSE-SU-2025:14968-1"],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PICSZDC3UGEUZ27VXGGM6OFI67D3KKLZ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IGO43JS7IFDNITHXOOHOP6JHRKRDIYY6/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1771"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jun/9"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4566-1/"},{"type":"ADVISORY","url":"https://www.cyrusimap.org/imap/download/release-notes/2.5/index.html"},{"type":"ADVISORY","url":"https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.13.html"},{"type":"ADVISORY","url":"https://www.cyrusimap.org/imap/download/release-notes/3.0/index.html"},{"type":"ADVISORY","url":"https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.10.html"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4458"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cyrusimap/cyrus-imapd","events":[{"introduced":"5549888feb02784120b7ef0c8a26390b83125108"},{"last_affected":"a4c4768f5eb8f1acb97b303aa3af3d26ef737612"},{"introduced":"65c252b8a3a05c09b3425ce96e1dc6a11dabbe4a"},{"last_affected":"fd5a57bcb4f7b32b330fd2b477d9e700e91ccf61"}],"database_specific":{"versions":[{"introduced":"2.5.0"},{"last_affected":"2.5.12"},{"introduced":"3.0.0"},{"last_affected":"3.0.9"}]}}],"versions":["cyrus-imapd-2.5.0","cyrus-imapd-2.5.1","cyrus-imapd-2.5.10","cyrus-imapd-2.5.11","cyrus-imapd-2.5.12","cyrus-imapd-2.5.2","cyrus-imapd-2.5.3","cyrus-imapd-2.5.4","cyrus-imapd-2.5.5","cyrus-imapd-2.5.6","cyrus-imapd-2.5.7","cyrus-imapd-2.5.8","cyrus-imapd-2.5.9","cyrus-imapd-3.0.0","cyrus-imapd-3.0.1","cyrus-imapd-3.0.2","cyrus-imapd-3.0.3","cyrus-imapd-3.0.4","cyrus-imapd-3.0.5","cyrus-imapd-3.0.6","cyrus-imapd-3.0.7","cyrus-imapd-3.0.8","cyrus-imapd-3.0.9"],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"29"}]},{"events":[{"introduced":"0"},{"last_affected":"30"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"18.04"}]},{"events":[{"introduced":"0"},{"last_affected":"8.0"}]},{"events":[{"introduced":"0"},{"last_affected":"8.1"}]},{"events":[{"introduced":"0"},{"last_affected":"8.2"}]},{"events":[{"introduced":"0"},{"last_affected":"8.4"}]},{"events":[{"introduced":"0"},{"last_affected":"8.2"}]},{"events":[{"introduced":"0"},{"last_affected":"8.4"}]},{"events":[{"introduced":"0"},{"last_affected":"8.2"}]},{"events":[{"introduced":"0"},{"last_affected":"8.4"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11356.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}