RETIRED: University of Washington IMAP c-client Remote Format String Vulnerability
BID:33795
CVE-2009-671 |Info
RETIRED: University of Washington IMAP c-client Remote Format String Vulnerability
| Bugtraq ID: | 33795 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2009 12:00AM |
| Updated: | Feb 24 2009 04:07PM |
| Credit: | Faryad Rahmany |
| Vulnerable: |
University of Washington imap 2007d |
| Not Vulnerable: | |
Discussion
RETIRED: University of Washington IMAP c-client Remote Format String Vulnerability
University of Washington IMAP 'c-client' is prone to a remote format-string vulnerability because the software fails to adequately sanitize user-supplied input before passing it as the format-specifier to a formatted-printing function.
Attackers can leverage this issue to execute arbitrary code in the context of applications built with the vulnerable library. Failed attacks will likely cause denial-of-service conditions.
IMAP 2007d is vulnerable; other versions may also be affected.
NOTE: This BID is being retired because the application is not vulnerable as described.
University of Washington IMAP 'c-client' is prone to a remote format-string vulnerability because the software fails to adequately sanitize user-supplied input before passing it as the format-specifier to a formatted-printing function.
Attackers can leverage this issue to execute arbitrary code in the context of applications built with the vulnerable library. Failed attacks will likely cause denial-of-service conditions.
IMAP 2007d is vulnerable; other versions may also be affected.
NOTE: This BID is being retired because the application is not vulnerable as described.
Exploit / POC
RETIRED: University of Washington IMAP c-client Remote Format String Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
RETIRED: University of Washington IMAP c-client Remote Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: University of Washington IMAP c-client Remote Format String Vulnerability
References:
References:
- IMAP Information Center (University of Washington)