CVE-2007-5467
Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long USER command containing "%s" sequences to the pop3 port (110/tcp), which are expanded to "%%s" before…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long USER command containing "%s" sequences to the pop3 port (110/tcp), which are expanded to "%%s" before being used in the memmove function, possibly due to an incomplete fix for CVE-2001-1078.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 13.52% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- extremail/extremail
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/27220
- http://www.digit-labs.org/files/exploits/extremail-v3.pl
- http://www.securityfocus.com/archive/1/482293
- http://www.securityfocus.com/bid/26074
- https://www.exploit-db.com/exploits/4532
- http://secunia.com/advisories/27220
- http://www.digit-labs.org/files/exploits/extremail-v3.pl
- http://www.securityfocus.com/archive/1/482293
- http://www.securityfocus.com/bid/26074
- https://www.exploit-db.com/exploits/4532
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.