Description
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1892-1 | New dovecot packages fix arbitrary code execution |
Debian DSA |
DSA-1893-1 | New cyrus-imapd-2.2/kolab-cyrus-imapd packages fix arbitrary code execution |
EUVD |
EUVD-2009-3218 | Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632. |
Ubuntu USN |
USN-838-1 | Dovecot vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T06:22:23.176Z
Reserved: 2009-09-16T00:00:00.000Z
Link: CVE-2009-3235
No data.
Status : Modified
Published: 2009-09-17T10:30:01.327
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-3235
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN