PT-2009-5028 · Cyrus+2 · Cyrus Imap+2

Nico Golde

·

Published

2009-09-08

·

Updated

2017-09-19

·

CVE-2009-2632

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions cyrus-imapd versions 2.2.13 through 2.3.14 Dovecot versions 1.0 through 1.0.3 Dovecot versions 1.1 through 1.1.6
Description A buffer overflow in the SIEVE script component, as used in cyrus-imapd and Dovecot, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script. This issue is related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
Recommendations For cyrus-imapd versions 2.2.13 through 2.3.14, update to a version that fixes the buffer overflow issue in the SIEVE script component. For Dovecot versions 1.0 through 1.0.3, update to version 1.0.4 or later. For Dovecot versions 1.1 through 1.1.6, update to version 1.1.7 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2632
DSA-1881-1
DSA-1892-1
DSA-1893-1
RHSA-2009:1459
RHSA-2009_1459

Affected Products

Dovecot
Red Hat
Cyrus Imap