7.5
CVSSv2

CVE-2009-3235

Published: 17/09/2009 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 prior to 1.0.4 and 1.1 prior to 1.1.7, as derived from Cyrus libsieve, allow context-dependent malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot 1.0.2

dovecot dovecot 1.0.3

dovecot dovecot 1.1.5

dovecot dovecot 1.1.6

dovecot dovecot 1.0.1

dovecot dovecot 1.1.1

dovecot dovecot 1.1.2

dovecot dovecot 1.1

dovecot dovecot 1.1.0

dovecot dovecot 1.0

dovecot dovecot 1.1.3

dovecot dovecot 1.1.4

Vendor Advisories

Debian Bug report logs - #546656 CVE-2009-3235: Multiple stack-based buffer overflows in the Sieve plugin in Dovecot Package: dovecot-common; Maintainer for dovecot-common is (unknown); Reported by: Pascal Volk <user@localhostlocaldomainorg> Date: Mon, 14 Sep 2009 21:18:02 UTC Severity: grave Tags: patch, security, upstr ...
It was discovered that the ACL plugin in Dovecot would incorrectly handle negative access rights An attacker could exploit this flaw to access the Dovecot server, bypassing the intended access restrictions This only affected Ubuntu 804 LTS (CVE-2008-4577) ...
It was discovered that the SIEVE component of dovecot, a mail server that supports mbox and maildir mailboxes, is vulnerable to a buffer overflow when processing SIEVE scripts This can be used to elevate privileges to the dovecot system user An attacker who is able to install SIEVE scripts executed by the server is therefore able to read and modi ...