// For flags

CVE-2008-5006

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

smtp.c in the c-client library in University of Washington IMAP Toolkit 2007b allows remote SMTP servers to cause a denial of service (NULL pointer dereference and application crash) by responding to the QUIT command with a close of the TCP connection instead of the expected 221 response code.

smtp.c en la biblioteca c-client en University of Washington IMAP Toolkit 2007b permite a servidores SMTP remotos provocar una denegación de servicio (referencia a puntero NULL y caída de aplicación) por responder al comando QUIT con un cierre de la conexión TCP en lugar de con el código de respuesta 221 esperado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-11-10 CVE Reserved
  • 2008-11-10 CVE Published
  • 2024-04-15 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
University Of Washington
Search vendor "University Of Washington"
Imap Toolkit
Search vendor "University Of Washington" for product "Imap Toolkit"
2007b
Search vendor "University Of Washington" for product "Imap Toolkit" and version "2007b"
-
Affected