Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://security.gentoo.org/glsa/glsa-200408-19.xml - | |
References | () http://www.securityfocus.com/bid/10976 - | |
References | () http://www.trustix.net/errata/2004/0043/ - | |
References | () http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=131 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/17034 - |
Information
Published : 2004-10-20 04:00
Updated : 2024-11-20 23:49
NVD link : CVE-2004-0777
Mitre link : CVE-2004-0777
CVE.ORG link : CVE-2004-0777
JSON object : View
Products Affected
inter7
- courier-imap
CWE
CWE-134
Use of Externally-Controlled Format String