CVE-2005-1521: Buffer Overflow
Published May 26, 2005
·Updated
Integer overflow in the fetchio function of the imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a partial message request with a large value in the END parameter, which leads to a heap-based buffer overflow.
Affected Software
2 affected components
GNU Mailutils=0.6
GNU Mailutils=0.5
Remediation
Patch Available
Event History
May 26, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1521?
CVE-2005-1521 is considered critical due to the potential for remote code execution.
2
How do I fix CVE-2005-1521?
To fix CVE-2005-1521, upgrade to GNU Mailutils version 0.6.90 or later.
3
What software is affected by CVE-2005-1521?
CVE-2005-1521 affects GNU Mailutils versions 0.5, 0.6, and earlier versions before 0.6.90.
4
What type of vulnerability is CVE-2005-1521?
CVE-2005-1521 is an integer overflow vulnerability that can lead to a heap-based buffer overflow.
5
Can CVE-2005-1521 be exploited remotely?
Yes, CVE-2005-1521 can be exploited remotely by sending crafted requests to the imap4d server.