CVE-2008-5514

Off-by-one error in the rfc822_output_char function in the RFC822BUFFER routines in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit before imap-2007e and other applications, allows context-dependent attackers to cause a denial of service (crash) via an e-mail message that triggers a buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
university_of_washingtonimap
𝑥
≤ 2007d
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
alpine
bullseye
2.24+dfsg1-1
fixed
etch
not-affected
lenny
no-dsa
bookworm
2.26+dfsg-1
fixed
sid
2.26+dfsg-2
fixed
trixie
2.26+dfsg-2
fixed
uw-imap
sid
8:2007f~dfsg-7
fixed
trixie
8:2007f~dfsg-7
fixed
bookworm
8:2007f~dfsg-7
fixed
bullseye
8:2007f~dfsg-7
fixed
etch
not-affected
lenny
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
uw-imap
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
not-affected
intrepid
ignored
hardy
ignored
gutsy
ignored
dapper
ignored