Possible Denial of Service with PHP and Cyrus IMAP on BSDi 4.2

From: Administrator (MG) (admin@eol.ca)
Date: 08/30/01


Message-ID: <006b01c13115$f9839930$3e03a8c0@gabalawi>
From: "Administrator (MG)" <admin@eol.ca>
To: <bugtraq@securityfocus.com>
Subject: Possible Denial of Service with PHP and Cyrus IMAP on BSDi 4.2
Date: Thu, 30 Aug 2001 01:38:18 -0400

Use of the php IMAP functions on BSDi webserver with Apache against a cyrus
server on BSDi 4.2 will eventually cause the mail server to hang, forcing a
hard reboot.

A BSDi 4.2 Cyrus server could be remotely DOS'd if external IMAP access is
available.

This has been experienced running IMP and Jawmail, two popular OSS webmail
packages which do not exhibit this behavior on other platforms.

This has been tested with the php compiled against c-client versions 2000
and 4.7, and with Cyrus 2.0.15 and 2.0.16 as the mail server.

The cyrus sever does not exhibit this behavior with regular mail clients.

It has also been tested with php 4.0.4pl1 and php 4.0.6

At this time, I am unable to determine if the issue is with the c-client or
with PHP.

M. Gamble
Echo Online Administration



Relevant Pages

  • Connecting to Gmail through IMAP with PHP - SSL context failed
    ... I'm trying to connect to Gmail through IMAP with PHP running in ... I've got some sort of PHP ... what I did to setup IMAP for PHP: ... also hookup Evolution (mail reader) to Gmail through IMAP and fetch ...
    (comp.lang.php)
  • Re: Help! (corier-imap + webmail)
    ... > because my PHP does not support IMAP. ... My PHP is the stock Debian ... phpgroupware-felamimail - phpGroupWare felamimail (Squirrelmail) module ...
    (Debian-User)
  • Re: Tips for a very fast PHP webmail
    ... list of messages using the imap function set of PHP and displaying the ... same amount of information using a simple SQL query from MySQL. ...
    (comp.lang.php)
  • Re: Using Php to receive - read email
    ... I want to use Php to ... >> IMAP functions ... >> Can I use Php functions to read email from a POP3 mailbox? ... >> Does anyone know of any tutorials or helpful web sites that might ...
    (comp.lang.php)
  • Re: Tips for a very fast PHP webmail
    ... list of messages using the imap function set of PHP and displaying the ... same amount of information using a simple SQL query from MySQL. ...
    (comp.lang.php)