Oval Definition:oval:com.redhat.rhsa:def:20091459
Revision Date:2009-09-23Version:640
Title:RHSA-2009:1459: cyrus-imapd security update (Important)
Description:The cyrus-imapd packages contain a high-performance mail server with IMAP, POP3, NNTP, and Sieve support.

  • Multiple buffer overflow flaws were found in the Cyrus IMAP Sieve implementation. An authenticated user able to create Sieve mail filtering rules could use these flaws to execute arbitrary code with the privileges of the Cyrus IMAP server user. (CVE-2009-2632, CVE-2009-3235)

    Users of cyrus-imapd are advised to upgrade to these updated packages, which contain backported patches to resolve these issues. After installing the update, cyrus-imapd will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-2632
    CVE-2009-3235
    RHSA-2009:1459
    RHSA-2009:1459-04
    RHSA-2009:1459-04
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • cyrus-imapd is earlier than 0:2.2.12-10.el4_8.4
  • AND cyrus-imapd is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-devel is earlier than 0:2.2.12-10.el4_8.4
  • AND cyrus-imapd-devel is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-murder is earlier than 0:2.2.12-10.el4_8.4
  • AND cyrus-imapd-murder is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-nntp is earlier than 0:2.2.12-10.el4_8.4
  • AND cyrus-imapd-nntp is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-utils is earlier than 0:2.2.12-10.el4_8.4
  • AND cyrus-imapd-utils is signed with Red Hat redhatrelease2 key
  • perl-Cyrus is earlier than 0:2.2.12-10.el4_8.4
  • AND perl-Cyrus is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • cyrus-imapd is earlier than 0:2.3.7-7.el5_4.3
  • AND cyrus-imapd is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-devel is earlier than 0:2.3.7-7.el5_4.3
  • AND cyrus-imapd-devel is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-perl is earlier than 0:2.3.7-7.el5_4.3
  • AND cyrus-imapd-perl is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-utils is earlier than 0:2.3.7-7.el5_4.3
  • AND cyrus-imapd-utils is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • cyrus-imapd is earlier than 0:2.2.12-10.el4_8.4
  • AND cyrus-imapd is signed with Red Hat master key
  • cyrus-imapd-devel is earlier than 0:2.2.12-10.el4_8.4
  • AND cyrus-imapd-devel is signed with Red Hat master key
  • cyrus-imapd-murder is earlier than 0:2.2.12-10.el4_8.4
  • AND cyrus-imapd-murder is signed with Red Hat master key
  • cyrus-imapd-nntp is earlier than 0:2.2.12-10.el4_8.4
  • AND cyrus-imapd-nntp is signed with Red Hat master key
  • cyrus-imapd-utils is earlier than 0:2.2.12-10.el4_8.4
  • AND cyrus-imapd-utils is signed with Red Hat master key
  • perl-Cyrus is earlier than 0:2.2.12-10.el4_8.4
  • AND perl-Cyrus is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • cyrus-imapd is earlier than 0:2.3.7-7.el5_4.3
  • AND cyrus-imapd is signed with Red Hat redhatrelease key
  • cyrus-imapd-devel is earlier than 0:2.3.7-7.el5_4.3
  • AND cyrus-imapd-devel is signed with Red Hat redhatrelease key
  • cyrus-imapd-perl is earlier than 0:2.3.7-7.el5_4.3
  • AND cyrus-imapd-perl is signed with Red Hat redhatrelease key
  • cyrus-imapd-utils is earlier than 0:2.3.7-7.el5_4.3
  • AND cyrus-imapd-utils is signed with Red Hat redhatrelease key
  • BACK