CVE-2017-12843: Cyrusimap Cyrus Imap
Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.
Affected products
- Cyrusimap Cyrus Imap: up to and including 3.0.2
- Fedoraproject Fedora: version 26 only
Published 2017-08-22. Last modified 2026-06-17.