Vulnerability Name: | CVE-2005-2878 (CCN-22212) | ||||||||
Assigned: | 2005-09-09 | ||||||||
Published: | 2005-09-09 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-2878 Source: BUGTRAQ Type: UNKNOWN 20050926 FreeBSD GNU Mailutils 0.6 imap4d exploit Source: CCN Type: GNU Mail Utilities Web Patch Web page GNU Mail Utilities - Patches: Item Detail: 4407 Source: CONFIRM Type: Patch http://savannah.gnu.org/patch/index.php?func=detailitem&item_id=4407 Source: CCN Type: SA16783 GNU Mailutils imap4d "SEARCH" Format String Vulnerability Source: SECUNIA Type: UNKNOWN 16783 Source: SECUNIA Type: UNKNOWN 17020 Source: DEBIAN Type: UNKNOWN DSA-841 Source: DEBIAN Type: DSA-841 mailutils -- format string vulnerability Source: CCN Type: GLSA-200509-10 Mailutils: Format string vulnerability in imap4d Source: GENTOO Type: UNKNOWN GLSA-200509-10 Source: IDEFENSE Type: Exploit, Patch, Vendor Advisory 20050909 GNU Mailutils 0.6 imap4d 'search' Format String Vulnerability Source: CCN Type: OSVDB ID: 19306 GNU Mailutils imap4d SEARCH Command Remote Format String Source: MISC Type: UNKNOWN http://www.rosiello.org/archivio/imap4d_FreeBSD_exploit.c Source: BID Type: UNKNOWN 14794 Source: CCN Type: BID-14794 GNU Mailutils Imap4D Search Command Remote Format String Vulnerability Source: XF Type: UNKNOWN gnumailutils-imap4d-utilfinish-format-string(22212) Source: CCN Type: iDefense Labs PUBLIC ADVISORY: 09.09.05 GNU Mailutils 0.6 imap4d 'search' Format String Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |