Description
Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.
Affected products
- inter7 / courier-imap1.6 – 1.6
- inter7 / courier-imap1.7 – 1.7
- inter7 / courier-imap2.0.0 – 2.0.0
- inter7 / courier-imap2.1 – 2.1
- inter7 / courier-imap2.1.1 – 2.1.1
- inter7 / courier-imap2.1.2 – 2.1.2
- inter7 / courier-imap2.2.0 – 2.2.0
- inter7 / courier-imap2.2.1 – 2.2.1
References
- MISChttp://www.trustix.net/errata/2004/0043/
- MISChttp://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=131
- MISChttp://www.securityfocus.com/bid/10976
- MISChttp://security.gentoo.org/glsa/glsa-200408-19.xml
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/17034