Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-07T05:59:56.175Z
Reserved: 2009-07-28T00:00:00
Link: CVE-2009-2632

No data.

Status : Deferred
Published: 2009-09-08T23:30:00.547
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-2632
