PT-2004-1388 · Courier · Courier-Imap+2
Published
2004-03-16
·
Updated
2017-07-11
·
CVE-2004-0224
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Courier-IMAP versions prior to 3.0.0
Courier versions prior to 0.45
SqWebMail versions prior to 4.0.0
Description
The issue is related to multiple buffer overflows in the iso2022jp.c or shiftjis.c files. This may allow remote attackers to execute arbitrary code when a Unicode character is out of the BMP range.
Recommendations
For Courier-IMAP versions prior to 3.0.0, update to version 3.0.0 or later.
For Courier versions prior to 0.45, update to version 0.45 or later.
For SqWebMail versions prior to 4.0.0, update to version 4.0.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Courier
Courier-Imap
Sqwebmail