PT-2004-2030 · Up · Up-Imapproxy

Timo Sirainen

·

Publicado

2004-11-16

·

Atualizado

2017-07-11

·

CVE-2004-1035

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions: up-imapproxy IMAP proxy version 1.2.2
Description: The issue is caused by multiple integer signedness errors in several files, including imapcommon.c, main.c, request.c, and select.c. These errors can be exploited by remote attackers to cause a denial of service, resulting in a server crash, and potentially leak sensitive information. This is achieved by sending certain literal values that are not properly handled when using the IMAP Line Read function.
Recommendations: For up-imapproxy IMAP proxy version 1.2.2, consider disabling the IMAP Line Read function until a patch is available to prevent potential exploitation. Restrict access to the affected files, including imapcommon.c, main.c, request.c, and select.c, to minimize the risk of server crash and sensitive information leakage.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1035

Produtos afetados

Up-Imapproxy