CVE-2021-40111

Description

In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP command could be used to trigger infinite loops resulting in expensive CPU computations and OutOfMemory exceptions. This can be used for a Denial Of Service attack. The IMAP user needs to be authenticated to exploit this vulnerability. This affected Apache James prior to version 3.6.1. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.585

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-40525,CVE-2021-40111,CVE-2021-38542,CVE-2021-40110 are fixed in Apache-james-server 3.6.1Windows
Vulnerabilities CVE-2021-40525,CVE-2021-40111,CVE-2021-38542,CVE-2021-40110 are fixed in Apache-james-server for Linux 3.6.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234