uw-imap: NULL pointer dereference in smtp.c
Published Nov 10, 2008
5.0
MEDIUMCVSS 2.0
EPSS 1.91%
Description
smtp.c in the c-client library in University of Washington IMAP Toolkit 2007b allows remote SMTP servers to cause a denial of service (NULL pointer dereference and application crash) by responding to the QUIT command with a close of the TCP connection instead of the expected 221 response code.
Affected products
No data.
- 2007b
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
The affected code is not used by any application shipped in Red Hat Enterprise Linux 2.1, 3, 4, and 5. The impact of this flaw is limited to a crash of the applications connecting to a misbehaving SMTP server. Due to those reasons, theres currently no plan to include the fix in the imap packages as shipped in Red Hat Enterprise Linux 2.1 and 3, and the libc-client packages as shipped in Red Hat Enterprise Linux 4 and 5.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.91% (0.01909) | 79.04th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.96% (0.01963) | 77.68th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.62% (0.00617) | 68.14th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.43% (0.00432) | 75.36th | v3 (v2023.03.01) |
| Apr 15, 2024 | 0.43% (0.00432) | 74.20th | v3 (v2023.03.01) |
| Mar 9, 2024 | 0.45% (0.00447) | 74.43th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.41% (0.00413) | 73.30th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.41% (0.00413) | 69.94th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.11% (0.01108) | 55.18th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.11% (0.01108) | 53.57th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.11% (0.01108) | 51.54th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.11% (0.01108) | 29.61th | v2 (v2022.01.01) |
References (10)
- http://secunia.com/advisories/33142 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2008/dsa-1685 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:146 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2008/11/03/5 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/32280 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2008-5006 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=470820 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46604 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2008-5006
- https://www.cve.org/CVERecord?id=CVE-2008-5006
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/33142 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.debian.org/security/2008/dsa-1685 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2009:146 | vendor-advisoryx_refsource_MANDRIVA | |
| http://www.openwall.com/lists/oss-security/2008/11/03/5 | mailing-listx_refsource_MLIST | |
| http://www.securityfocus.com/bid/32280 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2008-5006 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=470820 | Issue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/46604 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2008-5006 | ||
| https://www.cve.org/CVERecord?id=CVE-2008-5006 |
Change history (0)
No recorded changes yet.