Back

HIGH

cyrus-impad: CMU sieve buffer overflows

Published Sep 17, 2009

Description

Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.

Affected products

Remediation

Red Hat mitigation

All these additional overflows are sprintf()s to static char buffers. On Red Hat Enterprise Linux 5 and later (including all current Fedora versoins), these overflows are caught by FORTIFY_SOURCE reducing the impact to controlled abort of one of the cyrus-imapd child processes that are later re-spawned by the master.

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 17, 2009
Updated Aug 7, 2024
Reserved Sep 16, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Sep 14, 2009
ENISA EUVD
Assigner mitre
Published Sep 17, 2009
Updated Aug 7, 2024
Exploited since n/a
EUVD-2009-3218