CVE-2008-5005
uw-imap - several vulnerabilities
EPSS 6.4%
描述
Multiple stack-based buffer overflows in (1) University of Washington IMAP Toolkit 2002 through 2007c, (2) University of Washington Alpine 2.00 and earlier, and (3) Panda IMAP allow (a) local users to gain privileges by specifying a long folder extension argument on the command line to the tmail or dmail program; and (b) remote attackers to execute arbitrary code by sending e-mail to a destination mailbox name composed of a username and '+' character followed by a long string, processed by the tmail or possibly dmail program.
如何修補 CVE-2008-5005
要修補 CVE-2008-5005,請將受影響套件升級到下列已修補版本。
- —升級至 7:2007d~dfsg-1 或更新版本
- —升級至 7:2002edebian1-13.1+etch1 或更新版本
- —升級至 2007b~dfsg-4+lenny1 或更新版本
- —升級至 2007b~dfsg-4+lenny3 或更新版本
CVE-2008-5005 正在被利用嗎?
中等 — EPSS 為 6.4%,可持續追蹤但非最高優先。
受影響套件(4)
- from 0, < 7:2007d~dfsg-1
- from 0, < 7:2002edebian1-13.1+etch1
- from 0, < 2007b~dfsg-4+lenny1
- from 0, < 2007b~dfsg-4+lenny3