Multiple buffer overflows in Cyrus Sieve / libSieve 2.1.2 and earlier allow remote attackers to execute arbitrary code via (1) a long header name, (2) a long IMAP flag, or (3) a script that generates a large number of errors that overflow the resulting error string.
References
Configurations
History
20 Nov 2024, 23:43
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2002-12/0019.html - Exploit | |
References | () http://www.securityfocus.com/bid/6294 - | |
References | () http://www.securityfocus.com/bid/6299 - | |
References | () http://www.securityfocus.com/bid/6300 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/10743 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/10779 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/10780 - |
Information
Published : 2002-12-31 05:00
Updated : 2024-11-20 23:43
NVD link : CVE-2002-2253
Mitre link : CVE-2002-2253
CVE.ORG link : CVE-2002-2253
JSON object : View
Products Affected
cyrus
- libsieve
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer