Off-by-one error in the rfc822_output_char function in the RFC822BUFFER routines in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit before imap-2007e and other applications, allows context-dependent attackers to cause a denial of service (crash) via an e-mail message that triggers a buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade alpineUpgrade uw-imap | Jul 30, 2024 | Dec 23, 2008 |
| Freebsd | — | Upgrade imap-uw | Dec 10, 2025 | Jan 11, 2009 |
| Gentoo Linux | — | Upgrade net-mail/uw-imap.Upgrade dev-lang/php.Upgrade net-libs/c-client. | Oct 30, 2017 | Dec 23, 2008 |
| Suse | — | Upgrade imapUpgrade imap-libUpgrade imap-devel | Feb 17, 2015 | Dec 23, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub