cyrus-impad: CMU sieve buffer overflows
Published Sep 17, 2009
7.5
HIGHCVSS 2.0
EPSS 4.04%
Description
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
Affected products
No data.
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.1
- 1.1.0
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.6
No data.
Red Hat Enterprise Linux 4
cyrus-imapd-0:2.2.12-10.el4_8.4
Fixed · RHSA-2009:1459
Red Hat Enterprise Linux 5
cyrus-imapd-0:2.3.7-7.el5_4.3
Fixed · RHSA-2009:1459
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | cyrus-imapd-0:2.2.12-10.el4_8.4 | Fixed | RHSA-2009:1459 |
| Red Hat Enterprise Linux 5 | cyrus-imapd-0:2.3.7-7.el5_4.3 | Fixed | RHSA-2009:1459 |
No package ranges for this CVE.
Remediation
Red Hat mitigation
All these additional overflows are sprintf()s to static char buffers. On Red Hat Enterprise Linux 5 and later (including all current Fedora versoins), these overflows are caught by FORTIFY_SOURCE reducing the impact to controlled abort of one of the cyrus-imapd child processes that are later re-spawned by the master.
References (22)
- http://dovecot.org/list/dovecot-news/2009-September/000135.html mailing-listx_refsource_MLISTPatchVendor Advisory
- http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/36698 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36713 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36904 third-party-advisoryx_refsource_SECUNIA
- http://support.apple.com/kb/HT3937 x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2009/09/14/3 mailing-listx_refsource_MLIST
- http://www.osvdb.org/58103 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/36377 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-838-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2009/2641 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2009/3184 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-3235 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=523910 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-3218 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53248 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-3235
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10515 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-3235
- https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00491.html vendor-advisoryx_refsource_FEDORAPatch
Change history (0)
No recorded changes yet.