Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2009-09-08T23:00:00
Updated: 2024-08-07T05:59:56.175Z
Reserved: 2009-07-28T00:00:00
Link: CVE-2009-2632
Vulnrichment
No data.
NVD
Status : Modified
Published: 2009-09-08T23:30:00.547
Modified: 2024-11-21T01:05:20.510
Link: CVE-2009-2632
Redhat