Release Date: | 2009-09-08 | |
Impact: | Important | What is this? |
Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error. Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
See more information about CVE-2009-2632 from MITRE CVE dictionary and NIST NVD
NOTE: The following CVSS metrics and score provided are preliminary and subject to review.
Base Score: | 4.4 |
Vector String: | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Version: | 2.0 |
Attack Vector: | Local |
Attack Complexity: | Medium |
Authentication: | None |
Confidentiality Impact: | Partial |
Integrity Impact: | Partial |
Availability Impact: | Partial |
Platform | Errata | Release Date |
Oracle Enterprise Linux version 4 (cyrus-imapd) | ELSA-2009-1459 | 2009-09-23 |
Oracle Linux version 5 (cyrus-imapd) | ELSA-2009-1459 | 2009-09-23 |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections: