CVE Vulnerabilities

CVE-2007-5740

Use of Externally-Controlled Format String

Published: Oct 31, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the mechanism.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

NameVendorStart VersionEnd Version
Perdition_mail_retrieval_proxyVergenet*1.17 (including)
PerditionUbuntudapper*
PerditionUbuntuedgy*
PerditionUbuntufeisty*
PerditionUbuntugutsy*
PerditionUbuntuupstream*

Potential Mitigations

References