Executive Summary
| Summary | |
|---|---|
| Title | Cyrus IMAPd buffer overflow vulnerability |
| Informations | |||
|---|---|---|---|
| Name | VU#336053 | First vendor Publication | 2009-09-09 |
| Vendor | VU-CERT | Last vendor Modification | 2009-09-11 |
| Severity (Vendor) | N/A | Revision | M |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:L/AC:M/Au:N/C:P/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 4.4 | Attack Range | Local |
| Cvss Impact Score | 6.4 | Attack Complexity | Medium |
| Cvss Expoit Score | 3.4 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Vulnerability Note VU#336053Cyrus IMAPd buffer overflow vulnerabilityOverviewThe Cyrus IMAP server contains a vulnerability that may allow an authenticated attacker to execute code.I. DescriptionThe Cyrus IMAP mail server supports the SIEVE mail filtering language. Cyrus IMAP versions 2.2 through 2.3.14 contain a buffer overflow vulnerability that may be triggered by a specially crafted SIEVE script. To install this type of script, the attacker would need to have direct access to a mail account on the server.II. ImpactAn attacker with the ability to install SIEVE scripts may be able to gain elevated privileges and use the new permissions to execute code, read other user's mail, or send spoofed email messages.III. SolutionUpdateThe Cyrus IMAP team has released an update to address this issue. See http//lists.andrew.cmu.edu/pipermail/cyrus-announce/2009-September/000068.ht... for more information. Systems Affected
References CreditThanks to the Cyrus IMAP development team and Bron Gondwana for information that was used in this report. This document was written by Ryan Giobbi. Other Information
|
Original Source
| Url : http://www.kb.cert.org/vuls/id/336053 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:10082 | |||
| Oval ID: | oval:org.mitre.oval:def:10082 | ||
| Title: | Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error. | ||
| Description: | Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-2632 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application | 2 |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 57843 | Cyrus IMAP Server (cyrus-imapd) SIEVE Script Component (sieve/script.c) Craft... |

VU#336053
(Medium)






