First published: Tue Sep 13 2005(Updated: )
Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Mailutils | =0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2878 has a high severity due to the potential for remote arbitrary code execution.
To fix CVE-2005-2878, upgrade GNU Mailutils to a version later than 0.6 that has addressed this vulnerability.
CVE-2005-2878 affects remote authenticated users who can exploit the format string vulnerability in the SEARCH command of the imap4d server in GNU Mailutils 0.6.
CVE-2005-2878 impacts systems running GNU Mailutils version 0.6 specifically.
Yes, CVE-2005-2878 can be exploited with relatively low effort by sending crafted SEARCH commands.