Affected versions:

- Apache James server through 3.7.5
- Apache James server 3.8.0 through 3.8.1

Description:

Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service 
through the abuse of IMAP literals from both authenticated and unauthenticated 
users, which could be used to cause unbounded memory allocation and very long 
computations

Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals.

Credit:

Xavier GUIMARD (reporter)
Benoit TELLIER (coordinator)

References:

https://james.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-37358

Reply via email to