PT-2005-2514 · Gnu · Gnu Mailutils

Infamous41Md

·

Publicado

2005-05-26

·

Atualizado

2008-09-05

·

CVE-2005-1521

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GNU Mailutils versions 0.5 through 0.6.89
Description The issue is related to an integer overflow in the fetch io function of the imap4d server, which can be exploited by remote attackers to execute arbitrary code. This is achieved through a partial message request with a large value in the END parameter, resulting in a heap-based buffer overflow.
Recommendations For GNU Mailutils versions 0.5 through 0.6.89, update to version 0.6.90 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1521
DSA-732-1

Produtos afetados

Gnu Mailutils