Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade uw-imap | Jul 30, 2024 | Oct 13, 2005 |
| Freebsd | — | Upgrade imap-uw | Dec 10, 2025 | Oct 5, 2005 |
| Gentoo Linux | — | Upgrade net-mail/uw-imap. | Oct 30, 2017 | Oct 13, 2005 |
| Suse | — | Upgrade imap-develUpgrade imap-lib | Feb 17, 2015 | Oct 13, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub