7.5
CVSSv2

CVE-2004-0777

Published: 20/10/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 up to and including 2.2.1 and 3.x up to and including 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote malicious users to execute arbitrary code.

Vulnerable Product Search on Vulmon Subscribe to Product

inter7 courier-imap 1.6

inter7 courier-imap 1.7

inter7 courier-imap 2.2.0

inter7 courier-imap 2.2.1

inter7 courier-imap 2.0.0

inter7 courier-imap 2.1

inter7 courier-imap 2.1.1

inter7 courier-imap 2.1.2

Exploits

/* courier-imap <= 302-r1 Remote Format String Vulnerability exploit Author: ktha at hush dot com Tested on FreeBSD 410-RELEASE with courier-imap-302 Special thanks goes to andrewg for providing the FreeBSD box Greetings: all the guys from irc pulltheplug com and irc netric org bash-205b$ /sm00ny-courier_imap_f ...