Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username.
https://www.ubuntu.com/usn/usn-37-1/
https://exchange.xforce.ibmcloud.com/vulnerabilities/18333