Giuseppe Iuculano
2009-Sep-21 18:24 UTC
[Secure-testing-team] Bug#547712: CVE-2009-2632: Buffer overflow in the SIEVE script component
Package: kolab-cyrus-imapd Severity: grave Tags: security -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for kolab-cyrus-imapd. CVE-2009-2632[0]: | Buffer overflow in the SIEVE script component (sieve/script.c), as | used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and | Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to | execute arbitrary code and read or modify arbitrary messages via a | crafted SIEVE script, related to the incorrect use of the sizeof | operator for determining buffer length, combined with an integer | signedness error. If you fix the vulnerability please also make sure to include the CVE id in your changelog entry. For further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2632 http://security-tracker.debian.net/tracker/CVE-2009-2632 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkq3xN0ACgkQNxpp46476aoKcwCfQN+gUb2JMpzFYvRnu8ZlfY3s 5bEAoI9ZX21e1dUaBdEG8KGnDrpWoHnI =BODE -----END PGP SIGNATURE-----