cbcvebase.
CVE-2009-2632
published 2009-09-08

CVE-2009-2632: Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and…

PriorityP419medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.48%
38.9th percentile
Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.

Affected

19 ranges
VendorProductVersion rangeFixed in
cmucyrus_imap_server
cmucyrus_imap_server
debiandovecot< dovecot 1:1.2.1-1 (bookworm)dovecot 1:1.2.1-1 (bookworm)
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot>= 0 < 1:1.2.1-11:1.2.1-1
dovecotdovecot>= 0 < 1:1.2.1-11:1.2.1-1
dovecotdovecot>= 0 < 1:1.2.1-11:1.2.1-1
dovecotdovecot>= 0 < 1:1.2.1-11:1.2.1-1

CVSS provenance

nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.