Oval Definition:oval:org.mitre.oval:tst:39014
Comment:cyrus-imapd-devel is earlier than 0:2.2.12-10.el4_8.4
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:14695
Object:oval:org.mitre.oval:obj:3584
State:oval:org.mitre.oval:ste:11250
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:10082
V
Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
2013-04-29
oval:org.mitre.oval:def:10515
V
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
2013-04-29
BACK