PT-2004-2030 · Up · Up-Imapproxy
Timo Sirainen
·
Publicado
2004-11-16
·
Atualizado
2017-07-11
·
CVE-2004-1035
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
up-imapproxy IMAP proxy version 1.2.2
Description:
The issue is caused by multiple integer signedness errors in several files, including imapcommon.c, main.c, request.c, and select.c. These errors can be exploited by remote attackers to cause a denial of service, resulting in a server crash, and potentially leak sensitive information. This is achieved by sending certain literal values that are not properly handled when using the IMAP Line Read function.
Recommendations:
For up-imapproxy IMAP proxy version 1.2.2, consider disabling the IMAP Line Read function until a patch is available to prevent potential exploitation. Restrict access to the affected files, including imapcommon.c, main.c, request.c, and select.c, to minimize the risk of server crash and sensitive information leakage.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Up-Imapproxy