Title : Redhat Security Update Fixes IMAP Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2005-2776 CVE ID : CVE-2005-2933
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-07
Technical Description
Redhat has released updated packages to correct a vulnerability identified in IMAP. This flaw is due to a stack overflow error in the "mail_valid_net_parse_work()" [src/c-client/mail.c] function that does not properly handle specially crafted mailbox names containing a quote (") character, which could be exploited by authenticated remote attackers to execute arbitrary commands with the privileges of the IMAP server. For additional information, see : VUPEN/ADV-2005-1953