7.5
CVSSv2

CVE-2005-1520

Published: 26/05/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions prior to 0.6.90, allows remote malicious users to execute arbitrary code via a crafted e-mail.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu mailutils 0.5

gnu mailutils 0.6

Vendor Advisories

"infamous41md" discovered several vulnerabilities in the GNU mailutils package which contains utilities for handling mail These problems can lead to a denial of service or the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following vulnerabilities CAN-2005-1520 Buffer overflow mail header handli ...

Exploits

source: wwwsecurityfocuscom/bid/13766/info GNU Mailutils mail is affected by an email header buffer overflow vulnerability The problem exists in the 'header_get_field_name()' function of the 'mailbox/headerc' source file and manifests while the software is processing superfluous email header values Ultimately a malicious attacker may ...