6.8
CVSSv2

CVE-2007-2958

Published: 27/08/2007 Updated: 29/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.

Vulnerable Product Search on Vulmon Subscribe to Product

sylpheed-claws sylpheed-claws 1.9.100

sylpheed-claws sylpheed-claws 2.10.0

sylpheed sylpheed 2.4.4

Vendor Advisories

Debian Bug report logs - #441854 CVE-2007-2958 format string vulnerability in incc Package: sylpheed-claws; Maintainer for sylpheed-claws is (unknown); Reported by: Nico Golde <nion@debianorg> Date: Tue, 11 Sep 2007 13:24:01 UTC Severity: normal Tags: security Found in version sylpheed-claws/105-51 Fixed in version s ...