PT-2008-6903 · Washington University · University Of Washington Imap Toolkit+1

Published

1970-01-01

·

Updated

2024-02-14

·

CVE-2008-5005

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions University of Washington IMAP Toolkit versions 2002 through 2007c University of Washington Alpine version 2.00 and earlier
Description The issue concerns multiple stack-based buffer overflows in the University of Washington IMAP Toolkit and Alpine, which can be exploited to gain privileges or execute arbitrary code. This can be achieved by specifying a long folder extension argument on the command line to the tmail or dmail program, or by sending an email to a destination mailbox name composed of a username and '+' character followed by a long string. The exploitation can be done remotely.
Recommendations For University of Washington IMAP Toolkit versions 2002 through 2007c: Update to a version later than 2007c to resolve the issue. For University of Washington Alpine version 2.00 and earlier: Update to a version later than 2.00 to resolve the issue. As a temporary workaround, consider restricting access to the tmail and dmail programs until a patch is available. Avoid using long folder extension arguments on the command line to these programs. Restrict the use of the '+' character in destination mailbox names to minimize the risk of exploitation.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2015-02399
BDU:2015-02400
BDU:2015-02401
BDU:2015-02402
BDU:2015-02403
CVE-2008-5005
DSA-1685-1
DTSA-174-1
DTSA-174-2
RHSA-2009:0275

Affected Products

Alpine
University Of Washington Imap Toolkit