PT-2026-83056 · Unknown · Managesieve
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
ManageSieve (affected versions not specified)
Description
An attacker with valid credentials can submit a Sieve script containing an extreme numeric literal. This triggers an out-of-bounds write during script compilation by the ManageSieve service, leading to memory corruption and a process crash. This results in a denial of service for script management and could potentially allow remote code execution.
Recommendations
Update to a non-vulnerable version.
Disable the ManageSieve service if remote Sieve script management is not required.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Managesieve