Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Patches » RHSA-2009:1459-04

Overview

Id RHSA-2009:1459-04
Name Red Hat 2009:1459-04 RHSA Important: cyrus-imapd security update for RHEL 5 x86
Vendor Name red_hat
Product None
Content Type Critical - 01 Critical - 01
Language(s)
Operating System(s) Linux 
Released On 23 Sep 2009 12:00:00

RHSA-2009:1459-04

Red Hat 2009:1459-04 RHSA Important: cyrus-imapd security update for RHEL 5 x86

Vendor Name

red_hat

Product

None

Released On

23 Sep 2009 12:00:00

Url

https://rhn.redhat.com/errata/RHSA-2009-1459.html

Description

LSAC(v2)
The cyrus-imapd packages contain a high-performance mail server with IMAP, POP3, NNTP, and Sieve support. Multiple buffer overflow flaws were found in the Cyrus IMAP Sieve implementation. An authenticated user able to create Sieve mail filtering rules could use these flaws to execute arbitrary code with the privileges of the Cyrus IMAP server user. (CVE-2009-2632, CVE-2009-3235) Users of cyrus-imapd are advised to upgrade to these updated packages, which contain backported patches to resolve these issues. After installing the update, cyrus-imapd will be restarted automatically.

Related Resources

Related Vulnerabilities

CVE-2009-2632   CVE-2009-3235  

Related Patches

None

Superseded Patches


Last Updated: 27 May 2016 11:15:05