4.3
CVSSv2

CVE-2008-5514

Published: 23/12/2008 Updated: 08/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Off-by-one error in the rfc822_output_char function in the RFC822BUFFER routines in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit before imap-2007e and other applications, allows context-dependent malicious users to cause a denial of service (crash) via an e-mail message that triggers a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

university of washington imap 2006h

university of washington imap 2006g

university of washington imap 2006

university of washington imap 2004

university of washington imap 2004g

university of washington imap 2002

university of washington imap 2001

university of washington imap 2001a

university of washington imap 2000

university of washington imap 2006j

university of washington imap 2006i

university of washington imap 2006a

university of washington imap 2007

university of washington imap 2004e

university of washington imap 2004f

university of washington imap 2002e

university of washington imap 2002f

university of washington imap

university of washington imap 2007b

university of washington imap 2006f

university of washington imap 2006e

university of washington imap 2006d

university of washington imap 2004a

university of washington imap 2004b

university of washington imap 2002a

university of washington imap 2002b

university of washington imap 2000a

university of washington imap 2000b

university of washington imap 2007a

university of washington imap 2006k

university of washington imap 2006c

university of washington imap 2006b

university of washington imap 2004c

university of washington imap 2004d

university of washington imap 2002c

university of washington imap 2002d

university of washington imap 2000c

Vendor Advisories

Debian Bug report logs - #510918 CVE-2008-5514: Off-by-one error Package: uw-imap; Maintainer for uw-imap is Magnus Holmgren <holmgren@debianorg>; Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Mon, 5 Jan 2009 23:09:01 UTC Severity: grave Tags: patch, security Found in version 8:2007b~dfsg-1 Fixe ...