4.3
CVE-2008-5514
- EPSS 1.76%
- Veröffentlicht 23.12.2008 18:30:03
- Zuletzt bearbeitet 16.06.2026 23:00:27
- Erkennungen
Off-by-one error in the rfc822_output_char function in the RFC822BUFFER routines in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit before imap-2007e and other applications, allows context-dependent attackers to cause a denial of service (crash) via an e-mail message that triggers a buffer overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
University Of Washington ≫ Imap Version <= 2007d
University Of Washington ≫ Imap Version 2000
University Of Washington ≫ Imap Version 2000a
University Of Washington ≫ Imap Version 2000b
University Of Washington ≫ Imap Version 2000c
University Of Washington ≫ Imap Version 2001
University Of Washington ≫ Imap Version 2001a
University Of Washington ≫ Imap Version 2002
University Of Washington ≫ Imap Version 2002a
University Of Washington ≫ Imap Version 2002b
University Of Washington ≫ Imap Version 2002c
University Of Washington ≫ Imap Version 2002d
University Of Washington ≫ Imap Version 2002e
University Of Washington ≫ Imap Version 2002f
University Of Washington ≫ Imap Version 2004
University Of Washington ≫ Imap Version 2004a
University Of Washington ≫ Imap Version 2004b
University Of Washington ≫ Imap Version 2004c
University Of Washington ≫ Imap Version 2004d
University Of Washington ≫ Imap Version 2004e
University Of Washington ≫ Imap Version 2004f
University Of Washington ≫ Imap Version 2004g
University Of Washington ≫ Imap Version 2006
University Of Washington ≫ Imap Version 2006a
University Of Washington ≫ Imap Version 2006b
University Of Washington ≫ Imap Version 2006c
University Of Washington ≫ Imap Version 2006d
University Of Washington ≫ Imap Version 2006e
University Of Washington ≫ Imap Version 2006f
University Of Washington ≫ Imap Version 2006g
University Of Washington ≫ Imap Version 2006h
University Of Washington ≫ Imap Version 2006i
University Of Washington ≫ Imap Version 2006j
University Of Washington ≫ Imap Version 2006k
University Of Washington ≫ Imap Version 2007
University Of Washington ≫ Imap Version 2007a
University Of Washington ≫ Imap Version 2007b
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.76% | 0.751 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://www.mandriva.com/security/advisories?name=MDVSA-2009:146
http://secunia.com/advisories/33275
http://secunia.com/advisories/33638
http://securitytracker.com/id?1021485
http://www.securityfocus.com/bid/32958
http://www.vupen.com/english/advisories/2008/3490
http://www.washington.edu/imap/documentation/RELNOTES.html
https://bugzilla.redhat.com/show_bug.cgi?id=477227
https://exchange.xforce.ibmcloud.com/vulnerabilities/47526
https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00846.html