CLA-2002:487Vendor advisory
http://distro.conectiva.com/atualizacoes?id=a&anuncio=000487 CVE-2002-0379
WU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (1)
Record summary
CVE-2002-0379 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001.315) with legacy RFC 1730 support, and imapd 2000.287 and earlier, allows remote authenticated users to execute arbitrary code via a long BODY request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBWU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (1)ExploitDB exploitby kortyNot analyzed1 file
ExploitDBWU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (2)ExploitDB exploitby 0x3a0x29 crewNot analyzed1 file
References
1220020510 wu-imap buffer overflow conditionmailing list
http://marc.info/?l=bugtraq&m=102107222100529&w=2 HPSBTL0205-043Vendor advisory
http://online.securityfocus.com/advisories/4167 wuimapd-partial-mailbox-bo(9055)vdb entry
http://www.iss.net/security_center/static/9055.php VU#961489Third-party advisory
http://www.kb.cert.org/vuls/id/961489 MDKSA-2002:034Vendor advisory
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-034.php ESA-20020607-013Vendor advisory
http://www.linuxsecurity.com/advisories/other_advisory-2120.html RHSA-2002:092Vendor advisory
http://www.redhat.com/support/errata/RHSA-2002-092.html 4713vdb entry
http://www.securityfocus.com/bid/4713 washington.eduConfirmation
http://www.washington.edu/imap/buffer.html wuimapd-authenticated-user-bo(10803)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10803 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0379