Back

MEDIUM

uw-imap: NULL pointer dereference in smtp.c

Published Nov 10, 2008

Description

smtp.c in the c-client library in University of Washington IMAP Toolkit 2007b allows remote SMTP servers to cause a denial of service (NULL pointer dereference and application crash) by responding to the QUIT command with a close of the TCP connection instead of the expected 221 response code.

Affected products

Remediation

Red Hat statement

The affected code is not used by any application shipped in Red Hat Enterprise Linux 2.1, 3, 4, and 5. The impact of this flaw is limited to a crash of the applications connecting to a misbehaving SMTP server. Due to those reasons, theres currently no plan to include the fix in the imap packages as shipped in Red Hat Enterprise Linux 2.1 and 3, and the libc-client packages as shipped in Red Hat Enterprise Linux 4 and 5.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 10, 2008
Updated Aug 7, 2024
Reserved Nov 10, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 3, 2008