First published: Mon Nov 10 2008(Updated: )
smtp.c in the c-client library in University of Washington IMAP Toolkit 2007b allows remote SMTP servers to cause a denial of service (NULL pointer dereference and application crash) by responding to the QUIT command with a close of the TCP connection instead of the expected 221 response code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
University of Washington IMAP | =2007b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5006 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2008-5006, upgrade to the latest version of the University of Washington IMAP Toolkit that addresses this vulnerability.
CVE-2008-5006 allows remote SMTP servers to execute a denial of service attack by causing the application to crash.
CVE-2008-5006 affects the University of Washington IMAP Toolkit version 2007b.
CVE-2008-5006 exploits the application by causing a NULL pointer dereference when the SMTP server responds incorrectly to the QUIT command.