CVE-2009-2632

Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.4 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
cmucyrus_imap_server
2.2.13
cmucyrus_imap_server
2.3.14
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dovecot
bullseye
1:2.3.13+dfsg1-2+deb11u1
fixed
bullseye (security)
1:2.3.13+dfsg1-2+deb11u2
fixed
bookworm
1:2.3.19.1+dfsg1-2.1+deb12u1
fixed
bookworm (security)
1:2.3.19.1+dfsg1-2.1+deb12u1
fixed
sid
1:2.3.21.1+dfsg1-1
fixed
trixie
1:2.3.21.1+dfsg1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cyrus-imapd-2.2
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
Fixed 2.2.13-14ubuntu3.1
released
intrepid
ignored
hardy
ignored
dapper
ignored
dovecot
oneiric
Fixed 1:1.1.11-0ubuntu9
released
natty
Fixed 1:1.1.11-0ubuntu9
released
maverick
Fixed 1:1.1.11-0ubuntu9
released
lucid
Fixed 1:1.1.11-0ubuntu9
released
karmic
Fixed 1:1.1.11-0ubuntu9
released
jaunty
Fixed 1:1.1.11-0ubuntu4.1
released
intrepid
Fixed 1:1.1.4-0ubuntu1.3
released
hardy
Fixed 1:1.0.10-1ubuntu5.2
released
dapper
not-affected
kolab-cyrus-imapd
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
ignored
dapper
ignored
References