The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the mechanism.
AV:N/AC:L/Au:N/C:P/I:P/A:P
31/10/2007
by Vergenet
16 years ago