First published: Sat Oct 25 2003(Updated: )
Format string vulnerability in send_message.c for Sylpheed-claws 0.9.4 through 0.9.6 allows remote SMTP servers to cause a denial of service (crash) in sylpheed via format strings in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sylpheed | =0.9.4 | |
Sylpheed | =0.9.5 | |
Sylpheed | =0.9.6 | |
Claws-Mail | =0.9.4 | |
Claws-Mail | =0.9.5 | |
Claws-Mail | =0.9.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0852 is classified as a moderate severity vulnerability due to its potential to cause a denial of service.
To mitigate CVE-2003-0852, users should upgrade to Sylpheed versions 0.9.7 or later, which contain the necessary patches.
CVE-2003-0852 affects Sylpheed versions 0.9.4 to 0.9.6 and Claws-Mail versions 0.9.4 to 0.9.6.
The impact of CVE-2003-0852 can lead to the application crashing due to unhandled format strings from remote SMTP servers.
Yes, CVE-2003-0852 can be remotely exploited by sending specially crafted messages to the vulnerable email clients.