PT-2007-3514 · Courier · Courier-Imap

Published

2007-04-24

·

Updated

2017-07-29

·

CVE-2007-2173

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Courier-IMAP versions 4.0.6-r2 and earlier, 4.1.x versions prior to 4.1.2-r1
Description The issue allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable. This is an eval injection vulnerability in the courier-imapd.indirect and courier-pop3d.indirect components of Courier-IMAP.
Recommendations For versions 4.0.6-r2 and earlier, update to version 4.0.6-r2 or later. For 4.1.x versions prior to 4.1.2-r1, update to version 4.1.2-r1 or later. As a temporary workaround, consider restricting the use of the XMAILDIR variable until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2173

Affected Products

Courier-Imap