CVE-2005-2661

up-imapproxy <1.2.4 - RCE

Title source: llm

Description

Format string vulnerability in the ParseBannerAndCapability function in main.c for up-imapproxy 1.2.3 and 1.2.4 allows remote IMAP servers to execute arbitrary code via format string specifiers in a banner or capability line.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Steve Kemp · cdoslinux
https://www.exploit-db.com/exploits/26340

Scores

EPSS 0.1968
EPSS Percentile 95.4%

Details

Status published
Products (2)
up-imapproxy/up-imapproxy 1.2.3
up-imapproxy/up-imapproxy 1.2.4
Published Oct 14, 2005
Tracked Since Feb 18, 2026