Oval Definition:oval:org.mitre.oval:def:8390
Revision Date:2014-06-23Version:18
Title:DSA-1892 dovecot -- buffer overflow
Description:It was discovered that the SIEVE component of dovecot, a mail server that supports mbox and maildir mailboxes, is vulnerable to a buffer overflow when processing SIEVE scripts. This can be used to elevate privileges to the dovecot system user. An attacker who is able to install SIEVE scripts executed by the server is therefore able to read and modify arbitrary email messages on the system.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-2632
CVE-2009-3235
DSA-1892
Platform(s):Debian GNU/Linux 4.0
Debian GNU/Linux 5.0
Product(s):dovecot
Definition Synopsis
  • Release section
  • Debian GNU/Linux 5.0 is installed
  • AND Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is armel
  • OR Installed architecture is mips
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND Packages section
  • dovecot-pop3d is earlier than 1.0.15-2.3+lenny1
  • OR dovecot-common is earlier than 1.0.15-2.3+lenny1
  • OR dovecot-imapd is earlier than 1.0.15-2.3+lenny1
  • OR dovecot-dev is earlier than 1.0.15-2.3+lenny1
  • OR Release section
  • Debian GNU/Linux 4.0 is installed.
  • AND Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND Packages section
  • dovecot-pop3d is earlier than 1.0.rc15-2etch5
  • OR dovecot-common is earlier than 1.0.rc15-2etch5
  • OR dovecot-imapd is earlier than 1.0.rc15-2etch5
  • BACK