CVE-2007-2958

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/08/2007
Last modified:
09/04/2025

Description

Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sylpheed:sylpheed:2.4.4:*:*:*:*:*:*:*
cpe:2.3:a:sylpheed-claws:sylpheed-claws:1.9.100:*:*:*:*:*:*:*
cpe:2.3:a:sylpheed-claws:sylpheed-claws:2.10.0:*:*:*:*:*:*:*