[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1893 cyrus-imapd-2.2 kolab-cyrus-imapd -- buffer overflow

ID: oval:org.mitre.oval:def:7879Date: (C)2009-12-15   (M)2024-01-23
Class: PATCHFamily: unix




It was discovered that the SIEVE component of cyrus-imapd and kolab-cyrus-imapd, the Cyrus mail system, is vulnerable to a buffer overflow when processing SIEVE scripts. This can be used to elevate privileges to the cyrus system user. An attacker who is able to install SIEVE scripts executed by the server is therefore able to read and modify arbitrary email messages on the system. The update introduced by DSA 1881-1 was incomplete and the issue has been given an additional CVE id due to its complexity.

Platform:
Debian 5.0
Debian 4.0
Product:
cyrus-imapd-2.2
kolab-cyrus-imapd
Reference:
DSA-1893
CVE-2009-2632
CVE-2009-3235
CVE    2
CVE-2009-3235
CVE-2009-2632
CPE    2
cpe:/o:debian:debian_linux:4.x
cpe:/o:debian:debian_linux:5.x

© SecPod Technologies