Summary
The remote host is missing an update to cyrus-imapd announced via advisory FEDORA-2009-9869.
Solution
Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update cyrus-imapd' at the command line.
For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2009-9869
Insight
Update Information:
Fixed multiple stack-based buffer overflows in libsieve, which allowed context- dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script.
ChangeLog:
* Fri Sep 18 2009 Michal Hlavinka - 2.3.15-1
- fix another buffer overflow in cyrus sieve (CVE-2009-3235) * Mon Sep 7 2009 Michal Hlavinka - 2.3.14-2
- fix buffer overflow in cyrus sieve (#521010)
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2009-3235 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities