CVE-2009-3235
published 2009-09-17CVE-2009-3235: Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.04%
89.5th percentile
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:1.2.1-1 (bookworm) | dovecot 1:1.2.1-1 (bookworm) |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | >= 0 < 1:1.2.1-1 | 1:1.2.1-1 |
| dovecot | dovecot | >= 0 < 1:1.2.1-1 | 1:1.2.1-1 |
| dovecot | dovecot | >= 0 < 1:1.2.1-1 | 1:1.2.1-1 |
| dovecot | dovecot | >= 0 < 1:1.2.1-1 | 1:1.2.1-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2009-09-28·CVSS 7.5
CVE-2008-4577 [HIGH] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Dovecot vulnerabilities
It was discovered that the ACL plugin in Dovecot would incorrectly handle
negative access rights. An attacker could exploit this flaw to access the
Dovecot server, bypassing the intended access restrictions. This only
affected Ubuntu 8.04 LTS. (CVE-2008-4577)
It was discovered that the ManageSieve service in Dovecot incorrectly
handled ".." in script names. A remote attacker could exploit this to read
and modify arbitrary sieve files on the server. This only affected Ubuntu
8.10. (CVE-2008-5301)
It was discovered that the Sieve plugin in Dovecot incorrectly handled
certain sieve scripts. An authenticated user could exploit this with a
crafted sieve script to cause a denial of service or possibly execute
arbitrary code. (CV
Red Hat
cyrus-impad: CMU sieve buffer overflows
vendor_redhat·2009-09-14·CVSS 4.4
CVE-2009-3235 [MEDIUM] CWE-121 cyrus-impad: CMU sieve buffer overflows
cyrus-impad: CMU sieve buffer overflows
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
Mitigation: All these additional overflows are sprintf()s to static char buffers. On Red Hat Enterprise Linux 5 and later (including all current Fedora versoins), these overflows are caught by FORTIFY_SOURCE reducing the impact to controlled abort of one of the cyrus-imapd child processes that are later re-spawned by the master.
Debian
CVE-2009-3235: dovecot - Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before ...
vendor_debian·2009·CVSS 4.4
CVE-2009-3235 [MEDIUM] CVE-2009-3235: dovecot - Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before ...
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
Scope: local
bookworm: resolved (fixed in 1:1.2.1-1)
bullseye: resolved (fixed in 1:1.2.1-1)
forky: resolved (fixed in 1:1.2.1-1)
sid: resolved (fixed in 1:1.2.1-1)
trixie: resolved (fixed in 1:1.2.1-1)
GHSA
GHSA-vm7h-xxvx-g2fw: Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1
ghsa_unreviewed·2022-05-02·CVSS 4.4
CVE-2009-3235 [MEDIUM] CWE-119 GHSA-vm7h-xxvx-g2fw: Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
OSV
CVE-2009-3235: Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1
osv·2009-09-17·CVSS 4.4
CVE-2009-3235 [MEDIUM] CVE-2009-3235: Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3235 cyrus-impad: CMU sieve buffer overflows
bugzilla·2009-09-17·CVSS 4.4
CVE-2009-3235 [MEDIUM] CVE-2009-3235 cyrus-impad: CMU sieve buffer overflows
CVE-2009-3235 cyrus-impad: CMU sieve buffer overflows
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3235 to the following vulnerability:
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot
1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve,
allow context-dependent attackers to cause a denial of service (crash)
and possibly execute arbitrary code via a crafted SIEVE script, as
demonstrated by forwarding an e-mail message to a large number of
recipients, a different vulnerability than CVE-2009-2632.
Note: Sieve implementation used in cyrus-imapd is affected by these issues too.
References:
http://dovecot.org/list/dovecot-news/2009-September/000135.html
http://www.kb.cert.org/vuls/id/336053 (for CVE-2009-2632)
Dovecot patches:
ht
Bugzilla
CVE-2009-2632 cyrus-imapd: buffer overflow in cyrus sieve
bugzilla·2009-09-03·CVSS 4.4
CVE-2009-2632 [MEDIUM] CVE-2009-2632 cyrus-imapd: buffer overflow in cyrus sieve
CVE-2009-2632 cyrus-imapd: buffer overflow in cyrus sieve
A buffer overflow flaw was discovered in cyrus sieve caused by an incorrect way used to determine size of a buffer (sizeof() used on pointer to heap-allocated memory). A malicious authenticated user able to edit sieve script could use this flaw to trigger server crash or execute arbitrary code with server privileges (run as user cyrus).
Discussion:
Created attachment 359636
Upstream patch which should be applicable to both 2.2 and 2.3 versions
---
Upstream commit:
http://lists.andrew.cmu.edu/pipermail/cyrus-cvs/2009-September/001253.html
http://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sieve/script.c.diff?r1=1.67&r2=1.68
---
This is CERT VU#336053.
---
Public now via Debian DSA 1881:
http://lists.debian.org/debian-sec
http://dovecot.org/list/dovecot-news/2009-September/000135.htmlhttp://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://secunia.com/advisories/36698http://secunia.com/advisories/36713http://secunia.com/advisories/36904http://support.apple.com/kb/HT3937http://www.openwall.com/lists/oss-security/2009/09/14/3http://www.osvdb.org/58103http://www.securityfocus.com/bid/36377http://www.ubuntu.com/usn/USN-838-1http://www.vupen.com/english/advisories/2009/2641http://www.vupen.com/english/advisories/2009/3184https://exchange.xforce.ibmcloud.com/vulnerabilities/53248https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10515https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00491.htmlhttp://dovecot.org/list/dovecot-news/2009-September/000135.htmlhttp://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://secunia.com/advisories/36698http://secunia.com/advisories/36713http://secunia.com/advisories/36904http://support.apple.com/kb/HT3937http://www.openwall.com/lists/oss-security/2009/09/14/3http://www.osvdb.org/58103http://www.securityfocus.com/bid/36377http://www.ubuntu.com/usn/USN-838-1http://www.vupen.com/english/advisories/2009/2641http://www.vupen.com/english/advisories/2009/3184https://exchange.xforce.ibmcloud.com/vulnerabilities/53248https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10515https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00491.html
2009-09-17
Published