OpenBSD VuXML: Documenting security issues in the OpenBSD Ports & Packages Collection

imap-uw -- buffer verflow vulnerability

Affected packages
imap-uw < 2004g

Details

VuXML ID 4c7b5bd4-372c-11da-a14b-00065bd5b0b6
Discovery 2005-10-04
Entry 2005-10-07

Remote exploitation of a buffer overflow vulnerability in the University of Washington's IMAP Server (UW-IMAP) allows attackers to execute arbitrary code. The vulnerability specifically exists due to insufficient bounds checking on user-supplied values. The mail_valid_net_parse_work() function in src/c-client/mail.c is responsible for obtaining and validating the specified mailbox name from user-supplied data. An error in the parsing of supplied mailbox names will continue to copy memory after a " character has been parsed until another " character is found.

References

CVE Name CAN-2005-2933
URL http://www.idefense.com/application/poi/displa?id=313&type=vulnerabilities&flashstatus=true