CVE-2003-0297
c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.74% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- university of washington/c-client · university of washington/imap-2002b · university of washington/pine
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=105294024124163&w=2
- http://www.redhat.com/support/errata/RHSA-2005-015.html
- http://www.redhat.com/support/errata/RHSA-2005-114.html
- http://www.securityfocus.com/archive/1/430302/100/0/threaded
- http://marc.info/?l=bugtraq&m=105294024124163&w=2
- http://www.redhat.com/support/errata/RHSA-2005-015.html
- http://www.redhat.com/support/errata/RHSA-2005-114.html
- http://www.securityfocus.com/archive/1/430302/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.