CVE-2008-5514

Off-by-one error in the rfc822_output_char function in the RFC822BUFFER routines in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit before imap-2007e and other applications, allows context-dependent attackers to cause a denial of service (crash) via an e-mail message that triggers a buffer overflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:university_of_washington:imap:*:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2000:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2000a:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2000b:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2000c:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2001:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2001a:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2002:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2002a:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2002b:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2002c:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2002d:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2002e:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2002f:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2004:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2004a:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2004b:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2004c:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2004d:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2004e:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2004f:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2004g:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2006:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2006a:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2006b:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2006c:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2006d:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2006e:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2006f:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2006g:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2006h:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2006i:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2006j:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2006k:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2007:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2007a:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:imap:2007b:*:*:*:*:*:*:*

History

21 Nov 2024, 00:54

Type Values Removed Values Added
References () http://secunia.com/advisories/33275 - () http://secunia.com/advisories/33275 -
References () http://secunia.com/advisories/33638 - () http://secunia.com/advisories/33638 -
References () http://securitytracker.com/id?1021485 - () http://securitytracker.com/id?1021485 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2009:146 - () http://www.mandriva.com/security/advisories?name=MDVSA-2009:146 -
References () http://www.securityfocus.com/bid/32958 - () http://www.securityfocus.com/bid/32958 -
References () http://www.vupen.com/english/advisories/2008/3490 - () http://www.vupen.com/english/advisories/2008/3490 -
References () http://www.washington.edu/imap/documentation/RELNOTES.html - () http://www.washington.edu/imap/documentation/RELNOTES.html -
References () https://bugzilla.redhat.com/show_bug.cgi?id=477227 - () https://bugzilla.redhat.com/show_bug.cgi?id=477227 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/47526 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/47526 -
References () https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00846.html - () https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00846.html -

Information

Published : 2008-12-23 18:30

Updated : 2024-11-21 00:54


NVD link : CVE-2008-5514

Mitre link : CVE-2008-5514

CVE.ORG link : CVE-2008-5514


JSON object : View

Products Affected

university_of_washington

  • imap
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer