CVE-2009-3235
Publication date 17 September 2009
Last updated 24 July 2024
Ubuntu priority
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
Status
Package | Ubuntu Release | Status |
---|---|---|
cyrus-imapd-2.2 | 11.10 oneiric |
Not affected
|
11.04 natty |
Not affected
|
|
10.10 maverick |
Not affected
|
|
10.04 LTS lucid |
Not affected
|
|
9.10 karmic | Ignored end of life | |
9.04 jaunty |
Fixed 2.2.13-14ubuntu3.1
|
|
8.10 intrepid | Ignored end of life | |
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Ignored end of life | |
dovecot | 11.10 oneiric |
Fixed 1:1.1.11-0ubuntu9
|
11.04 natty |
Fixed 1:1.1.11-0ubuntu9
|
|
10.10 maverick |
Fixed 1:1.1.11-0ubuntu9
|
|
10.04 LTS lucid |
Fixed 1:1.1.11-0ubuntu9
|
|
9.10 karmic |
Fixed 1:1.1.11-0ubuntu9
|
|
9.04 jaunty |
Fixed 1:1.1.11-0ubuntu4.1
|
|
8.10 intrepid |
Fixed 1:1.1.4-0ubuntu1.3
|
|
8.04 LTS hardy |
Fixed 1:1.0.10-1ubuntu5.2
|
|
6.06 LTS dapper |
Not affected
|
|
kolab-cyrus-imapd | 11.10 oneiric |
Not affected
|
11.04 natty |
Not affected
|
|
10.10 maverick |
Not affected
|
|
10.04 LTS lucid |
Not affected
|
|
9.10 karmic | Ignored end of life | |
9.04 jaunty | Ignored end of life | |
8.10 intrepid | Ignored end of life | |
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Ignored end of life |
Notes
mdeslaur
version specified is of dovecot-sieve, not of the dovecot itself although code is present in dapper’s dovecot, we don’t compile the sieve plugin
Patch details
Package | Patch details |
---|---|
cyrus-imapd-2.2 |
|
dovecot |