CVE-2007-5740
perdition - format string vulnerability
EPSS 12.4%
描述
The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the mechanism.
如何修補 CVE-2007-5740
要修補 CVE-2007-5740,請將受影響套件升級到下列已修補版本。
- Debian/perdition—升級至 1.17.1-1 或更新版本
- Debian/perdition—升級至 1.17-7etch1 或更新版本
- Debian/perdition—升級至 1.17-8+lenny1 或更新版本
CVE-2007-5740 正在被利用嗎?
中等 — EPSS 為 12.4%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 1.17.1-1
- from 0, < 1.17-7etch1
- from 0, < 1.17-8+lenny1