PT-2003-1504 · Washington University · C-Client Imap Client+1
Timo Sirainen
·
Published
2003-05-15
·
Updated
2018-10-19
·
CVE-2003-0297
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
c-client IMAP Client versions as used in imap-2002b and Pine 4.53
Description:
The issue allows remote malicious IMAP servers to cause a denial of service, potentially leading to a crash, and may also allow the execution of arbitrary code. This is achieved through certain large literal and mailbox size values that cause either integer signedness errors or integer overflow errors.
Recommendations:
For c-client IMAP Client versions as used in imap-2002b and Pine 4.53, consider restricting access to the IMAP server until a fix is available to prevent potential exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pine
C-Client Imap Client