CVE-2005-0667: Buffer Overflow
Published Mar 7, 2005
·Updated
Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.
Affected Software
27 affected components
Sylpheed Sylpheed=0.8.11
Sylpheed Sylpheed=0.9.4
Sylpheed Sylpheed=0.9.5
Sylpheed Sylpheed=0.9.6
Sylpheed Sylpheed=0.9.7
Sylpheed Sylpheed=0.9.8
Sylpheed Sylpheed=0.9.9
Sylpheed Sylpheed=0.9.10
Sylpheed Sylpheed=0.9.11
Sylpheed Sylpheed=0.9.12
Sylpheed Sylpheed=0.9.99
Sylpheed Sylpheed=1.0.0
Sylpheed Sylpheed=1.0.1
Sylpheed Sylpheed=1.0.2
Sylpheed-claws Sylpheed-claws=1.0.2
Altlinux Alt Linux=2.3
Altlinux Alt Linux=2.3
Gentoo Linux
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Fedora Core=core_3.0
redhat Linux Advanced Workstation=2.1
redhat Linux Advanced Workstation=2.1
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Mar 7, 2005
CVE Published
05:00 AM
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0667?
CVE-2005-0667 is considered a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2005-0667?
To fix CVE-2005-0667, upgrade Sylpheed to version 1.0.3 or later.
3
Which versions of Sylpheed are affected by CVE-2005-0667?
CVE-2005-0667 affects Sylpheed versions prior to 1.0.3 and all versions before 1.9.5.
4
What type of attack does CVE-2005-0667 enable?
CVE-2005-0667 enables remote attackers to execute arbitrary code via specially crafted email messages.
5
Is there a workaround for CVE-2005-0667?
As a workaround for CVE-2005-0667, users can avoid opening untrusted email messages or disable automatic replies.