Format string vulnerability in the ParseBannerAndCapability function in main.c for up-imapproxy 1.2.3 and 1.2.4 allows remote IMAP servers to execute arbitrary code via format string specifiers in a banner or capability line.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Up-imapproxy | Up-imapproxy | 1.2.3 (including) | 1.2.3 (including) |
Up-imapproxy | Up-imapproxy | 1.2.4 (including) | 1.2.4 (including) |
Up-imapproxy | Ubuntu | dapper | * |
Up-imapproxy | Ubuntu | devel | * |
Up-imapproxy | Ubuntu | edgy | * |
Up-imapproxy | Ubuntu | feisty | * |