PublicDate: 2007-08-27 17:17:00 UTC Candidate: CVE-2007-2958 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2958 Description: Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_sylpheed-claws-gtk2: released (2.1.1-1ubuntu1.1) edgy_sylpheed-claws-gtk2: released (2.5.0~rc3-1ubuntu0.1) feisty_sylpheed-claws-gtk2: released (2.6.0-1.1ubuntu1.1) gutsy_sylpheed-claws-gtk2: DNE devel_sylpheed-claws-gtk2: DNE dapper_claws-mail: DNE edgy_claws-mail: DNE feisty_claws-mail: DNE gutsy_claws-mail: released (2.10.0-3ubuntu3) devel_claws-mail: released (2.10.0-3ubuntu3) dapper_sylpheed: released (2.2.4-1ubuntu1.1) edgy_sylpheed: released (2.2.7-1ubuntu0.1) feisty_sylpheed: released (2.3.1-1~ubuntu1.1) gutsy_sylpheed: released (2.4.5-1) devel_sylpheed: released (2.4.5-1) dapper_sylpheed-claws: released (1.0.5-2ubuntu0.1) edgy_sylpheed-claws: released (1.0.5-4ubuntu0.1) feisty_sylpheed-claws: released (1.0.5-5.1ubuntu0.1) gutsy_sylpheed-claws: DNE devel_sylpheed-claws: DNE upstream_claws-mail: needs-triage upstream_sylpheed: needs-triage upstream_sylpheed-claws: needs-triage upstream_sylpheed-claws-gtk2: needs-triage