Back
CVE-2005-2878
Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command.
Published: Sep 13, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| gnu | mailutils | 0.6 |
GitHub Security Advisory GHSA-6mvq-9mv3-ppcp
Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote...
References (18)
- http://marc.info/?l=bugtraq&m=112785181316043&w=2
- http://savannah.gnu.org/patch/index.php?func=detailitem&item_id=4407 Patch
- http://secunia.com/advisories/16783
- http://secunia.com/advisories/17020
- http://www.debian.org/security/2005/dsa-841
- http://www.gentoo.org/security/en/glsa/glsa-200509-10.xml
- http://www.idefense.com/application/poi/display?id=303&type=vulnerabilities&flashstatus=true Exploit, Patch, Vendor Advisory
- http://www.rosiello.org/archivio/imap4d_FreeBSD_exploit.c
- http://www.securityfocus.com/bid/14794
- http://marc.info/?l=bugtraq&m=112785181316043&w=2
- http://savannah.gnu.org/patch/index.php?func=detailitem&item_id=4407 Patch
- http://secunia.com/advisories/16783
- http://secunia.com/advisories/17020
- http://www.debian.org/security/2005/dsa-841
- http://www.gentoo.org/security/en/glsa/glsa-200509-10.xml
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
14.57%
Top 4% most likely to be exploited
Threat Score
34.4 / 100
Data Sources
NVD
EPSS
GitHub