[pkg-kolab] Bug#547712: CVE-2009-2632: Buffer overflow in the SIEVE script component

Giuseppe Iuculano giuseppe at iuculano.it
Mon Sep 21 18:24:36 UTC 2009


Package: kolab-cyrus-imapd
Severity: grave
Tags: security

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for kolab-cyrus-imapd.

CVE-2009-2632[0]:
| Buffer overflow in the SIEVE script component (sieve/script.c), as
| used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and
| Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to
| execute arbitrary code and read or modify arbitrary messages via a
| crafted SIEVE script, related to the incorrect use of the sizeof
| operator for determining buffer length, combined with an integer
| signedness error.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2632
    http://security-tracker.debian.net/tracker/CVE-2009-2632


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkq3xN0ACgkQNxpp46476aoKcwCfQN+gUb2JMpzFYvRnu8ZlfY3s
5bEAoI9ZX21e1dUaBdEG8KGnDrpWoHnI
=BODE
-----END PGP SIGNATURE-----





More information about the pkg-kolab-devel mailing list