PT-2007-3514 · Courier · Courier-Imap
Publicado
2007-04-24
·
Atualizado
2017-07-29
·
CVE-2007-2173
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Courier-IMAP versions 4.0.6-r2 and earlier, 4.1.x versions prior to 4.1.2-r1
Description
The issue allows remote attackers to execute arbitrary commands via the
XMAILDIR variable, related to the LOGINRUN variable. This is an eval injection vulnerability in the courier-imapd.indirect and courier-pop3d.indirect components of Courier-IMAP.Recommendations
For versions 4.0.6-r2 and earlier, update to version 4.0.6-r2 or later.
For 4.1.x versions prior to 4.1.2-r1, update to version 4.1.2-r1 or later.
As a temporary workaround, consider restricting the use of the
XMAILDIR variable until a patch is available.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Courier-Imap