漏洞信息详情
libSieve头名称缓冲区溢出漏洞
- CNNVD编号:CNNVD-200212-343
- 危害等级: 超危
- CVE编号:
CVE-2002-2253
- 漏洞类型:
缓冲区溢出
- 发布时间:
2002-12-31
- 威胁类型:
远程
- 更新时间:
2002-12-31
- 厂 商:
cyrus - 漏洞来源:
Discovery of this … -
漏洞简介
Cyrus Sieve / libSieve 2.1.2及其更早版本存在多个缓冲区溢出漏洞。远程攻击者可以借助(1)超长头名称,(2)超长IMAP标志,(3)能够生成大量错误并溢出这些错误字符串的脚本执行任意代码。
漏洞公告
An unofficial patch has been made available by Timo Sirainen
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com
参考网址
来源: XF
名称: cyrus-sieve-script-bo(10780)
链接:http://xforce.iss.net/xforce/xfdb/10780
来源: XF
名称: cyrus-sieve-imap-bo(10779)
链接:http://xforce.iss.net/xforce/xfdb/10779
来源: XF
名称: cyrus-sieve-header-bo(10743)
链接:http://xforce.iss.net/xforce/xfdb/10743
来源: BID
名称: 6300
链接:http://www.securityfocus.com/bid/6300
来源: BID
名称: 6299
链接:http://www.securityfocus.com/bid/6299
来源: BID
名称: 6294
链接:http://www.securityfocus.com/bid/6294
来源: BUGTRAQ
名称: 20021202 Cyrus Sieve / libSieve buffer overflow
链接:http://archives.neohapsis.com/archives/bugtraq/2002-12/0019.html