[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252212

 
 

909

 
 

196748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-0100Date: (C)2005-02-07   (M)2023-12-22


Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-12462
http://marc.info/?l=bugtraq&m=110780416112719&w=2
DSA-670
DSA-671
DSA-685
FLSA-2006:152898
MDKSA-2005:038
RHSA-2005:110
RHSA-2005:112
RHSA-2005:133
oval:org.mitre.oval:def:9408
xemacs-movemail-format-string(19246)

CPE    3
cpe:/a:gnu:emacs
cpe:/a:gnu:emacs:21.3
cpe:/a:gnu:xemacs

© SecPod Technologies