libSieve头名称缓冲区溢出漏洞

漏洞信息详情

libSieve头名称缓冲区溢出漏洞

漏洞简介

Cyrus Sieve / libSieve 2.1.2及其更早版本存在多个缓冲区溢出漏洞。远程攻击者可以借助(1)超长头名称,(2)超长IMAP标志,(3)能够生成大量错误并溢出这些错误字符串的脚本执行任意代码。

漏洞公告

An unofficial patch has been made available by Timo Sirainen and can be obtained from the referenced advisory.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com .
@securityfocus.com>
@iki.fi>

参考网址

来源: XF
名称: cyrus-sieve-script-bo(10780)
链接:http://xforce.iss.net/xforce/xfdb/10780

来源: XF
名称: cyrus-sieve-imap-bo(10779)
链接:http://xforce.iss.net/xforce/xfdb/10779

来源: XF
名称: cyrus-sieve-header-bo(10743)
链接:http://xforce.iss.net/xforce/xfdb/10743

来源: BID
名称: 6300
链接:http://www.securityfocus.com/bid/6300

来源: BID
名称: 6299
链接:http://www.securityfocus.com/bid/6299

来源: BID
名称: 6294
链接:http://www.securityfocus.com/bid/6294

来源: BUGTRAQ
名称: 20021202 Cyrus Sieve / libSieve buffer overflow
链接:http://archives.neohapsis.com/archives/bugtraq/2002-12/0019.html

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享