CVE-2005-2933

    Dashboard / Vulnerabilities / CVE-2005-2933

    CVE-2005-2933

    Published: 13 Oct 2005Last Modified: 10 Apr 2026

    Summary:

    Details: Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.

    References: ftp://patches.sgi.com/support/free/security/advisories/20051201-01-U, ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc, http://rhn.redhat.com/errata/RHSA-2006-0276.html, http://rhn.redhat.com/errata/RHSA-2006-0549.html, http://secunia.com/advisories/17062/, http://secunia.com/advisories/17148, http://secunia.com/advisories/17152, http://secunia.com/advisories/17215, http://secunia.com/advisories/17276, http://secunia.com/advisories/17336, http://secunia.com/advisories/17483, http://secunia.com/advisories/17928, http://secunia.com/advisories/17930, http://secunia.com/advisories/17950, http://secunia.com/advisories/18554, http://secunia.com/advisories/19832, http://secunia.com/advisories/20210, http://secunia.com/advisories/20222, http://secunia.com/advisories/20951, http://secunia.com/advisories/21252, http://secunia.com/advisories/21564, http://www.debian.org/security/2005/dsa-861, http://www.idefense.com/application/poi/display?id=313&type=vulnerabilities&flashstatus=true, http://www.mandriva.com/security/advisories?name=MDKSA-2005:189, http://www.mandriva.com/security/advisories?name=MDKSA-2005:194, http://www.novell.com/linux/security/advisories/2005_23_sr.html, http://www.vupen.com/english/advisories/2006/2685, http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0081.html, http://secunia.com/advisories/17062/, http://www.idefense.com/application/poi/display?id=313&type=vulnerabilities&flashstatus=true, http://www.washington.edu/imap/, http://securityreason.com/securityalert/47, http://securitytracker.com/id?1015000, http://slackware.com/security/viewer.php?l=slackware-security&y=2005&m=slackware-security.500161, http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm, http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm, http://www.gentoo.org/security/en/glsa/glsa-200510-10.xml, http://www.kb.cert.org/vuls/id/933601, http://www.redhat.com/support/errata/RHSA-2005-848.html, http://www.redhat.com/support/errata/RHSA-2005-850.html, http://www.redhat.com/support/errata/RHSA-2006-0501.html, http://www.securityfocus.com/archive/1/430296/100/0/threaded, http://www.securityfocus.com/archive/1/430303/100/0/threaded, http://www.securityfocus.com/bid/15009, https://exchange.xforce.ibmcloud.com/vulnerabilities/22518, https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9858

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High