Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range."
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade courier | Jul 30, 2024 | Apr 15, 2004 |
| Freebsd | — | Upgrade sqwebmailUpgrade courierUpgrade courier-imap | Dec 10, 2025 | Mar 31, 2004 |
| Gentoo Linux | — | Upgrade net-mail/courier-imap.Upgrade mail-mta/courier. | Oct 30, 2017 | Apr 15, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub