First published: Thu May 15 2003(Updated: )
c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
University of Washington IMAP | ||
University of Washington c-client | ||
University of Washington PINE | =4.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0297 is classified as a moderate severity vulnerability due to its potential for denial of service and arbitrary code execution.
To fix CVE-2003-0297, upgrade to a patched version of the affected software, such as a newer version of IMAP or Pine.
CVE-2003-0297 affects University of Washington IMAP 2002b, c-client, and Pine version 4.53.
CVE-2003-0297 can be exploited by remote malicious IMAP servers delivering specially crafted large literal and mailbox size values.
The consequences of CVE-2003-0297 include crashes of the IMAP client and the potential execution of arbitrary code on the user's system.