Back

MEDIUM

CVE-2007-2958 claws-mail format string vulnerability

Published Aug 27, 2007

Description

Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect version of Sylpheed as shipped with Red Hat Enterprise Linux 2.1. Sylpheed and claws-mail are not shipped with Red Hat Enterprise Linux 3, 4, or 5.

Metrics

Weaknesses (0)

No CWE recorded.

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner flexera
Published Aug 27, 2007
Updated Aug 7, 2024
Reserved May 31, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Aug 23, 2007