CVE-2005-2878
mailutils - Format string vulnerability
EPSS 14.6%
Description
Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command.
How to fix CVE-2005-2878
To remediate CVE-2005-2878, upgrade the affected package to a fixed version below.
- Debian/mailutils—upgrade to 1:0.6.90-3 or later
- Debian/mailutils—upgrade to 1:0.6.1-4sarge1 or later
- Debian/mailutils—upgrade to 1:0.6.90-2.1etch1 or later
Is CVE-2005-2878 being exploited?
Moderate — EPSS is 14.6%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 1:0.6.90-3
- from 0, < 1:0.6.1-4sarge1
- from 0, < 1:0.6.90-2.1etch1