CVE-2009-2632: Buffer Overflow
Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2632?
CVE-2009-2632 has a high severity rating due to the potential for local users to execute arbitrary code.
How do I fix CVE-2009-2632?
To fix CVE-2009-2632, update to the latest version of Cyrus IMAP Server or Dovecot that includes the security patch.
Which versions are affected by CVE-2009-2632?
CVE-2009-2632 affects Cyrus IMAP Server versions 2.2.13 and 2.3.14, as well as Dovecot versions before 1.0.4 and 1.1 before 1.1.7.
What kind of attack does CVE-2009-2632 allow?
CVE-2009-2632 allows local users to execute arbitrary code and manipulate email messages through crafted SIEVE scripts.
Is there a workaround for CVE-2009-2632?
There are no specific workarounds for CVE-2009-2632; upgrading to a patched version is the recommended approach.