PT-2005-3782 · Washington University+1 · Uw-Imap+1

Infamous41Md

·

Published

2005-10-13

·

Updated

2018-10-19

·

CVE-2005-2933

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions UW-IMAP versions prior to 2004g
Description The issue is related to a buffer overflow in the mail valid net parse work function in mail.c. This occurs when a mailbox name contains a single double-quote character without a closing quote, causing bytes after the double-quote to be copied into a buffer indefinitely. This can allow remote attackers to execute arbitrary code.
Recommendations For versions prior to 2004g, update to version 2004g or later to resolve the issue. As a temporary workaround, consider restricting the use of special characters in mailbox names to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2933
DSA-861-1
RHSA-2005:848
RHSA-2005:850
RHSA-2005_848
RHSA-2005_850
RHSA-2006:0276
RHSA-2006_0276

Affected Products

Red Hat
Uw-Imap