Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Sylpheed and Sylpheed-Claws POP3 Format String Vulnerability

Sylpheed and Sylpheed-Claws are prone to a format-string vulnerability.

This issue presents itself because the applications fail to properly sanitize POP3 server error responses that contain format specifiers.

A successful attack may crash the application or possibly lead to arbitrary code execution. This may facilitate unauthorized access or privilege escalation in the context of the user running the application.

Sylpheed 2.4.4, Sylpheed-Claws 1.9.100, and Sylpheed-Claws 'Claws Mail' 2.10.0 are vulnerable to this issue; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus