Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-3235

Опубликовано: 17 сент. 2009
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5

Описание

Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

2.2.13-19
hardy

ignored

end of life
intrepid

ignored

end of life
jaunty

released

2.2.13-14ubuntu3.1
karmic

ignored

end of life
lucid

not-affected

2.2.13-19
maverick

not-affected

2.2.13-19
natty

not-affected

2.2.13-19
oneiric

not-affected

2.2.13-19

Показывать по

РелизСтатусПримечание
dapper

not-affected

code not compiled
devel

released

1:1.1.11-0ubuntu9
hardy

released

1:1.0.10-1ubuntu5.2
intrepid

released

1:1.1.4-0ubuntu1.3
jaunty

released

1:1.1.11-0ubuntu4.1
karmic

released

1:1.1.11-0ubuntu9
lucid

released

1:1.1.11-0ubuntu9
maverick

released

1:1.1.11-0ubuntu9
natty

released

1:1.1.11-0ubuntu9
oneiric

released

1:1.1.11-0ubuntu9

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

2.2.13-9
hardy

ignored

end of life
intrepid

ignored

end of life
jaunty

ignored

end of life
karmic

ignored

end of life
lucid

not-affected

2.2.13-9
maverick

not-affected

2.2.13-9
natty

not-affected

2.2.13-9
oneiric

not-affected

2.2.13-9

Показывать по

7.5 High

CVSS2

Связанные уязвимости

redhat
почти 16 лет назад

Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.

nvd
почти 16 лет назад

Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.

debian
почти 16 лет назад

Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1 ...

github
около 3 лет назад

Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.

oracle-oval
больше 15 лет назад

ELSA-2009-1459: cyrus-imapd security update (IMPORTANT)

7.5 High

CVSS2