CVE-2003-0852: Medium severity Sylpheed Sylpheed vulnerability
Format string vulnerability in sendmessage.c for Sylpheed-claws 0.9.4 through 0.9.6 allows remote SMTP servers to cause a denial of service (crash) in sylpheed via format strings in an error message.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0852?
CVE-2003-0852 is classified as a moderate severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2003-0852?
To mitigate CVE-2003-0852, users should upgrade to Sylpheed versions 0.9.7 or later, which contain the necessary patches.
Which versions are affected by CVE-2003-0852?
CVE-2003-0852 affects Sylpheed versions 0.9.4 to 0.9.6 and Claws-Mail versions 0.9.4 to 0.9.6.
What is the impact of CVE-2003-0852?
The impact of CVE-2003-0852 can lead to the application crashing due to unhandled format strings from remote SMTP servers.
Is CVE-2003-0852 remotely exploitable?
Yes, CVE-2003-0852 can be remotely exploited by sending specially crafted messages to the vulnerable email clients.