Gnu Mailutils imap4d "search" Command Remote Format String Exploit

Posted by tadelste on Sep 11, 2005 7:26 AM EDT
K-OTik Décideurs
Mail this story
Print this story

A vulnerability was identified in GNU Mailutils, which could be exploited by remote attackers to execute arbitrary commands. This flaw is due to a format string error in the "util_finish()" function that does not properly handle specially crafted "SEARCH" commands, which could be exploited by authenticated remote attackers to execute arbitrary commands on a vulnerable system.

Full Story

  Nav
» Read more about: Story Type: News Story; Groups: GNU

« Return to the newswire homepage

This topic does not have any threads posted yet!

You cannot post until you login.