FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

perdition -- str_vwrite format string vulnerability

Affected packages
perdition < 1.17.1

Details

VuXML ID 617a4021-8bf0-11dc-bffa-0016179b2dd5
Discovery 2007-10-31
Entry 2007-11-05

SEC-Consult reports:

Perdition IMAP is affected by a format string bug in one of its IMAP output-string formatting functions. The bug allows the execution of arbitrary code on the affected server. A successful exploit does not require prior authentication.

References

Bugtraq ID 26270
CVE Name CVE-2007-5740
URL http://secunia.com/advisories/27458
URL http://www.sec-consult.com/300.html