CVE-2000-0284: Buffer Overflow
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
University of Washington UW-IMAP (imapd 4.7)from your environment.Uninstall or stop the affected imapd 4.7 daemon (University of Washington UW-IMAP) until a vendor-supplied fix is available.
- Compensating control
If immediate removal is not possible, block or restrict access to the IMAP service (imapd) at the network perimeter or host-based firewall to trusted IPs only, and/or disable IMAP service to prevent exploitation until patched.
- Operational
Audit IMAP usage and server logs for suspicious LIST or other command activity from authenticated accounts; rotate passwords/credentials for accounts that may have been used or are at risk and monitor for further abuse.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0284?
CVE-2000-0284 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2000-0284?
To fix CVE-2000-0284, update to a patched version of University of Washington imapd, specifically version 12.264 or later.
Who is affected by CVE-2000-0284?
Users with a valid account on University of Washington imapd version 12.264 are affected by CVE-2000-0284.
What systems are impacted by CVE-2000-0284?
CVE-2000-0284 impacts systems running University of Washington imapd version 12.264.
What type of attack is associated with CVE-2000-0284?
CVE-2000-0284 may allow attackers to execute arbitrary commands through specially crafted LIST or other commands.