Synopsis
The remote openSUSE host is missing one or more security updates.
Description
The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:20962-1 advisory.
Changes in cyrus-imapd:
- cyrus-imapd don't start because of missing Requires=var-run.mount from systemd (bsc#1251788) Remove var-run.mount from Requires and After
- update to version 3.8.6 (bugfix release) VUL-0: CVE-2025-49812: cyrus-imapd: Opossum Attack Application Layer Desynchronization using Opportunistic TLS (bsc#1246165) The industry is deprecating STARTTLS (aka opportunistic TLS) in favor of implicit TLS over a dedicated port. STARTTLS is now disabled by default.
* Fixed issue #5477: master: tighten up pidfile/etc handling (bsc#1241543) VUL-0: cyrus-imapd: privilege drop happens too late, opening attack vectors from cyrus to root
* Fixed issue #5450: fix zoneinfo_db code for GCC 15 (thanks Yadd)
* Fixed issue #5309: deadlock on shutdown (thanks Mark Cammidge)
* Fixed issue #5424: recognise service-specific SASL options in ``cyr_info conf-lint``
* Fixed issue #5420: fix double-free in http_admin (thanks Wolfgang Breyha)
* Fixed issue #5460: pop3d: add basic prometheus support (thanks Wolfgang Breyha)
* Fixed issue #5454: httpd fails to parse OpenSSL version for status string
- update to version 3.8.5 (bugfix release)
* Fixed Issue #5029: check for unexpected extra tiny-tests directories
* Fixed Issue #5148: added --enable-release-checks configure option for use when building releases
* Fixed Issue #4489: calendar-color changes namespace (thanks )
* Fixed Issue #5009: various portability warnings and nits
* Fixed Issue #5050: iTIP line endings (thanks )
* Fixed Issue #5052: iMIP line endings (thanks )
* Fixed Issue #5072: http_cgi use after free (thanks )
* Fixed Issue #5094: httpd crash when PROPFIND url is /dav/calendars
* Fixed Issue #5118: broken language checks for zr-hant and sr-me
* Fixed Issue #5047: proxying UID SEARCH
- CVE-2025-23394: cyrus-imapd: daily-backup.sh allows escalation from cyrus to root (bsc#1241536)
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected packages.
Plugin Details
File Name: openSUSE-2026-20962-1.nasl
Agent: unix
Supported Sensors: Nessus Agent, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
CPE: p-cpe:/a:novell:opensuse:cyrus-imapd, p-cpe:/a:novell:opensuse:cyrus-imapd-devel, p-cpe:/a:novell:opensuse:perl-cyrus-imap, p-cpe:/a:novell:opensuse:perl-cyrus-sieve-managesieve, p-cpe:/a:novell:opensuse:cyradm, p-cpe:/a:novell:opensuse:cyrus-imapd-snmp, p-cpe:/a:novell:opensuse:cyrus-imapd-snmp-mibs, p-cpe:/a:novell:opensuse:cyrus-imapd-utils, cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:libcyrus0, p-cpe:/a:novell:opensuse:perl-cyrus-annotator
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: No known exploits are available
Patch Publication Date: 6/12/2026
Vulnerability Publication Date: 2/12/2025