CVE-2009-3235
Publication date 17 September 2009
Last updated 24 July 2024
Ubuntu priority
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
Status
Package | Ubuntu Release | Status |
---|---|---|
cyrus-imapd-2.2 | ||
dovecot | ||
kolab-cyrus-imapd | ||
Notes
mdeslaur
version specified is of dovecot-sieve, not of the dovecot itself although code is present in dapper's dovecot, we don't compile the sieve plugin
Patch details
Package | Patch details |
---|---|
cyrus-imapd-2.2 |
|
dovecot |