Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade sylpheed | Jul 30, 2024 | Aug 27, 2007 |
| Freebsd | — | Upgrade sylpheed-clawsUpgrade sylpheed2Upgrade claws-mail | Dec 10, 2025 | Aug 27, 2007 |
| Gentoo Linux | — | Upgrade mail-client/claws-mail.Upgrade mail-client/sylpheed. | Oct 30, 2017 | Aug 27, 2007 |
| Suse | — | Upgrade sylpheed-clawsUpgrade claws-mail-develUpgrade suse-releaseUpgrade claws-mail | Feb 17, 2015 | Aug 27, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub