CVE-2005-2661
up-imapproxy - arbitrary code execution
EPSS 12.1%
Description
Format string vulnerability in the ParseBannerAndCapability function in main.c for up-imapproxy 1.2.3 and 1.2.4 allows remote IMAP servers to execute arbitrary code via format string specifiers in a banner or capability line.
How to fix CVE-2005-2661
To remediate CVE-2005-2661, upgrade the affected package to a fixed version below.
- Debian/up-imapproxy—upgrade to 1.2.4-2 or later
- Debian/up-imapproxy—upgrade to 1.2.3-1sarge1 or later
Is CVE-2005-2661 being exploited?
Moderate — EPSS is 12.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 1.2.4-2
- from 0, < 1.2.3-1sarge1