CVE-2019-11356: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 7.6% chance of exploitation in the next 30 days.

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only
  • Cyrus Imap: from 2.5.0, up to and including 2.5.12; from 3.0.0, up to and including 3.0.9
  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only

Published 2019-06-03. Last modified 2026-06-17.