Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1892-1 | New dovecot packages fix arbitrary code execution |
Debian DSA |
DSA-1893-1 | New cyrus-imapd-2.2/kolab-cyrus-imapd packages fix arbitrary code execution |
EUVD |
EUVD-2009-2626 | Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error. |
Ubuntu USN |
USN-838-1 | Dovecot vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-07T05:59:56.175Z
Reserved: 2009-07-28T00:00:00
Link: CVE-2009-2632
No data.
Status : Deferred
Published: 2009-09-08T23:30:00.547
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-2632
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN