Vulnerability Name: | CVE-2008-5006 (CCN-46604) | ||||||||||||||||||||
Assigned: | 2008-11-03 | ||||||||||||||||||||
Published: | 2008-11-03 | ||||||||||||||||||||
Updated: | 2017-08-08 | ||||||||||||||||||||
Summary: | smtp.c in the c-client library in University of Washington IMAP Toolkit 2007b allows remote SMTP servers to cause a denial of service (NULL pointer dereference and application crash) by responding to the QUIT command with a close of the TCP connection instead of the expected 221 response code. | ||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-noinfo CWE-399 | ||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||
References: | Source: CCN Type: IMAP FTP page Index of ftp://ftp.cac.washington.edu/imap/ Source: MITRE Type: CNA CVE-2008-5006 Source: SECUNIA Type: UNKNOWN 33142 Source: DEBIAN Type: UNKNOWN DSA-1685 Source: DEBIAN Type: DSA-1685 uw-imap -- buffer overflows Source: MANDRIVA Type: UNKNOWN MDVSA-2009:146 Source: CCN Type: oss-security Mailing List, Mon, 3 Nov 2008 16:37:43 +0100 Re: CVE request - uw-imap Source: MLIST Type: UNKNOWN [oss-security] 20081103 Re: CVE request - uw-imap Source: CCN Type: OSVDB ID: 49793 IMAP Toolkit c-client Library smtp.c Malformed QUIT Command Syntax Remote DoS Source: BID Type: UNKNOWN 32280 Source: CCN Type: BID-32280 University of Washington IMAP 'smtp.c' Null Pointer Dereference Denial of Service Vulnerability Source: CCN Type: IMAP Web page IMAP Information Center Source: XF Type: UNKNOWN imap-toolkit-smtp-dos(46604) Source: XF Type: UNKNOWN imap-toolkit-smtp-dos(46604) Source: SUSE Type: SUSE-SR:2009:001 SUSE Security Summary Report | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |