cbcvebase.
CVE-2009-3235
published 2009-09-17

CVE-2009-3235: Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow…

PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.04%
89.5th percentile
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandovecot< dovecot 1:1.2.1-1 (bookworm)dovecot 1:1.2.1-1 (bookworm)
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot>= 0 < 1:1.2.1-11:1.2.1-1
dovecotdovecot>= 0 < 1:1.2.1-11:1.2.1-1
dovecotdovecot>= 0 < 1:1.2.1-11:1.2.1-1
dovecotdovecot>= 0 < 1:1.2.1-11:1.2.1-1

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.