CVE-2008-7074
25.08.2009, 10:30
Format string vulnerability in MemeCode Software i.Scribe 1.88 through 2.00 before Beta9 allows remote SMTP servers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a server response, which is not properly handled "when displaying the signon message."Enginsight
Vendor | Product | Version |
---|---|---|
memcode | i.scribe | 1.88 |
memcode | i.scribe | 1.89 |
memcode | i.scribe | 1.90 |
memcode | i.scribe | 2.00:alpha1 |
memcode | i.scribe | 2.00:alpha2 |
memcode | i.scribe | 2.00:alpha3 |
memcode | i.scribe | 2.00:alpha4 |
memcode | i.scribe | 2.00:beta10 |
memcode | i.scribe | 2.00:beta11 |
memcode | i.scribe | 2.00:beta6 |
memcode | i.scribe | 2.00:beta7 |
memcode | i.scribe | 2.00:beta8 |
memcode | i.scribe | 2.00:beta9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References