Summary
The remote host is missing an update to up-imapproxy announced via advisory DSA 852-1.
Steve Kemp discovered two format string vulnerabilities in up-imapproxy, an IMAP protocol proxy, which may lead remote attackers to the execution of arbitrary code.
The old stable distribution (woody) is not affected by these problems.
Solution
For the stable distribution (sarge) this problem has been fixed in version 1.2.3-1sarge1.
For the unstable distribution (sid) this problem has been fixed in version 1.2.4-2.
We recommend that you upgrade your imapproxy package.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20852-1
Severity
Classification
-
CVE CVE-2005-2661 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities