Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Dovecot | — | Upgrade macOS to the latest version | Dec 16, 2011 | Sep 17, 2009 |
| Centos_linux | — | Upgrade cyrus-imapd-develUpgrade cyrus-imapd-nntpUpgrade cyrus-imapd-perlUpgrade perl-CyrusUpgrade cyrus-imapdUpgrade cyrus-imapd-murderUpgrade cyrus-imapd-utils | Dec 1, 2016 | Sep 17, 2009 |
| Debian | — | Upgrade dovecot | Jul 30, 2024 | Sep 17, 2009 |
| Gentoo Linux | — | Upgrade net-mail/dovecot. | Oct 30, 2017 | Sep 17, 2009 |
| Oracle_linux | — | Upgrade cyrus-imapd-utilsUpgrade cyrus-imapd-perlUpgrade cyrus-imapdUpgrade cyrus-imapd-devel | Oct 16, 2024 | Sep 17, 2009 |
| Suse | — | Upgrade perl-Cyrus-SIEVE-managesieveUpgrade cyrus-imapdUpgrade cyrus-imapd-develUpgrade perl-Cyrus-IMAP | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade dovecot-common | Nov 8, 2024 | Sep 17, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub