CVE-2007-5740
perdition - format string vulnerability
EPSS 12.4%
Description
The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the mechanism.
How to fix CVE-2007-5740
To remediate CVE-2007-5740, upgrade the affected package to a fixed version below.
- Debian/perdition—upgrade to 1.17.1-1 or later
- Debian/perdition—upgrade to 1.17-7etch1 or later
- Debian/perdition—upgrade to 1.17-8+lenny1 or later
Is CVE-2007-5740 being exploited?
Moderate — EPSS is 12.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 1.17.1-1
- from 0, < 1.17-7etch1
- from 0, < 1.17-8+lenny1