libSieve Error Message Buffer Overrun Vulnerability
BID:6300
Info
libSieve Error Message Buffer Overrun Vulnerability
| Bugtraq ID: | 6300 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 03 2002 12:00AM |
| Updated: | Dec 03 2002 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Timo Sirainen <[email protected]>. |
| Vulnerable: |
Cyrusoft libSieve 2.1.2 |
| Not Vulnerable: | |
Discussion
libSieve Error Message Buffer Overrun Vulnerability
A vulnerability has been discovered in the Sieve library. By generating excessive error messages in a program linked to the vulnerable library it is possible to overrun a buffer. Overwriting sensitive memory with attacker-supplied values may make it possible to execute arbitrary instructions with privileges of the vulnerable process.
A vulnerability has been discovered in the Sieve library. By generating excessive error messages in a program linked to the vulnerable library it is possible to overrun a buffer. Overwriting sensitive memory with attacker-supplied values may make it possible to execute arbitrary instructions with privileges of the vulnerable process.
Exploit / POC
libSieve Error Message Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
libSieve Error Message Buffer Overrun Vulnerability
Solution:
An unofficial patch has been made available by Timo Sirainen <[email protected]> and can be obtained from the referenced advisory.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
An unofficial patch has been made available by Timo Sirainen <[email protected]> and can be obtained from the referenced advisory.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
libSieve Error Message Buffer Overrun Vulnerability
References:
References:
- Cyrus Sieve / libSieve buffer overflow (Timo Sirainen
)