PublicDate: 2007-10-31 16:46:00 UTC Candidate: CVE-2007-5740 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5740 Description: The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the mechanism. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/perdition/+bug/162543 Priority: medium Discovered-by: Assigned-to: shermann CVSS: dapper_perdition: released (1.17-5ubuntu0.1) edgy_perdition: released (1.17-7ubuntu0.6.10.1) feisty_perdition: released (1.17-7ubuntu0.7.04.1) gutsy_perdition: released (1.17-7ubuntu0.7.10.1) devel_perdition: not-affected upstream_perdition: released (1.17.1)