Description
Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1892-1 | New dovecot packages fix arbitrary code execution |
Debian DSA |
DSA-1893-1 | New cyrus-imapd-2.2/kolab-cyrus-imapd packages fix arbitrary code execution |
EUVD |
EUVD-2009-2626 | Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error. |
Ubuntu USN |
USN-838-1 | Dovecot vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-07T05:59:56.175Z
Reserved: 2009-07-28T00:00:00.000Z
Link: CVE-2009-2632
No data.
Status : Modified
Published: 2009-09-08T23:30:00.547
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-2632
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN