Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-2958

Опубликовано: 27 авг. 2007
Источник: debian

Описание

Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sylpheed-clawsfixed1.0.5-5.2package
sylpheed-clawsno-dsaetchpackage
sylpheed-clawsno-dsasargepackage
sylpheedfixed2.4.5-1package
sylpheedno-dsaetchpackage
sylpheedno-dsasargepackage

Примечания

  • the cvs referenced in redhat bugzilla is not available anymore however

  • http://www.colino.net/claws-mail/getpatchset.php3?ver=2.10.0cvs153 fixes the bug

Связанные уязвимости

ubuntu
больше 18 лет назад

Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.

redhat
больше 18 лет назад

Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.

nvd
больше 18 лет назад

Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.

github
почти 4 года назад

Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.