PT-2003-1504 · Washington University · C-Client Imap Client+1

Timo Sirainen

·

Published

2003-05-15

·

Updated

2018-10-19

·

CVE-2003-0297

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: c-client IMAP Client versions as used in imap-2002b and Pine 4.53
Description: The issue allows remote malicious IMAP servers to cause a denial of service, potentially leading to a crash, and may also allow the execution of arbitrary code. This is achieved through certain large literal and mailbox size values that cause either integer signedness errors or integer overflow errors.
Recommendations: For c-client IMAP Client versions as used in imap-2002b and Pine 4.53, consider restricting access to the IMAP server until a fix is available to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0297

Affected Products

Pine
C-Client Imap Client