Title : Mutt "browse_get_namespace" IMAP Namespace Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2006-2522 CVE ID : CVE-2006-3242
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-06-26
Technical Description
A vulnerability has been identified in Mutt, which may be exploited by attackers to execute arbitrary code. This flaw is due to a buffer overflow error in the "browse_get_namespace()" [imap/browse.c] function that does not properly handle an overly long namespace received from the IMAP server, which could be exploited by attackers to crash an affected application or compromise a vulnerable system by convincing a user to connect to a malicious IMAP server.