CVE-2007-5740

Vergenet Perdition Mail Retrieval Proxy - Format String Vulnerability

Title source: rule
STIX 2.1

Description

The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the mechanism.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Bernhard Mueller · textdoslinux
https://www.exploit-db.com/exploits/30724

References (11)

Core 11
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27520
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018883
Various Sources x_refsource_confirm
http://www.vergenet.net/linux/perdition/ChangeLog.shtml
Various Sources x_refsource_misc
http://www.sec-consult.com/300.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2007/dsa-1398
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27458
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/38184
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3677
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/483034/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26270

Scores

EPSS 0.2546
EPSS Percentile 96.2%

Details

CWE
CWE-134
Status published
Products (1)
vergenet/perdition_mail_retrieval_proxy < 1.17
Published Oct 31, 2007
Tracked Since Feb 18, 2026