4.3
CVSSv2

CVE-2008-5514

Published: 23/12/2008 Updated: 08/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Off-by-one error in the rfc822_output_char function in the RFC822BUFFER routines in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit before imap-2007e and other applications, allows context-dependent malicious users to cause a denial of service (crash) via an e-mail message that triggers a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

university_of_washington imap 2002

university_of_washington imap 2006e

university_of_washington imap 2004b

university_of_washington imap 2004d

university_of_washington imap 2004f

university_of_washington imap 2006a

university_of_washington imap 2002d

university_of_washington imap 2002f

university_of_washington imap 2004

university_of_washington imap 2006k

university_of_washington imap 2004a

university_of_washington imap 2004c

university_of_washington imap 2001a

university_of_washington imap 2006j

university_of_washington imap 2000

university_of_washington imap 2006f

university_of_washington imap 2006h

university_of_washington imap 2002a

university_of_washington imap

university_of_washington imap 2007

university_of_washington imap 2001

university_of_washington imap 2006

university_of_washington imap 2007a

university_of_washington imap 2007b

university_of_washington imap 2006b

university_of_washington imap 2006c

university_of_washington imap 2004e

university_of_washington imap 2000b

university_of_washington imap 2002b

university_of_washington imap 2006i

university_of_washington imap 2000a

university_of_washington imap 2004g

university_of_washington imap 2000c

university_of_washington imap 2002c

university_of_washington imap 2006d

university_of_washington imap 2002e

university_of_washington imap 2006g

Vendor Advisories

Debian Bug report logs - #510918 CVE-2008-5514: Off-by-one error Package: uw-imap; Maintainer for uw-imap is Magnus Holmgren <holmgren@debianorg>; Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Mon, 5 Jan 2009 23:09:01 UTC Severity: grave Tags: patch, security Found in version 8:2007b~dfsg-1 Fixe ...