Fedora Account System
Red Hat Associate
Red Hat Customer
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall. References: https://cyrus.topicbox.com/groups/announce/T126392718bc29d6b/cyrus-imap-3-2-7-released https://www.cyrusimap.org/imap/download/release-notes/3.4/x/3.4.1.html https://www.cyrusimap.org/imap/download/release-notes/3.2/x/3.2.7.html https://cyrus.topicbox.com/groups/announce/T056901c106ecfce3/cyrus-imap-3-4-1-released
Created cyrus-imapd tracking bugs for this issue: Affects: fedora-all [bug 1959139]
Upstream commit for this issue: https://github.com/cyrusimap/cyrus-imapd/commit/621f9e41465b521399f691c241181300fab55995