CVE-2008-5006
Estado: ModificadaMedia (5)—
smtp.c in the c-client library in University of Washington IMAP Toolkit 2007b allows remote SMTP servers to cause a denial of service (NULL pointer dereference and application crash) by responding to the QUIT command with a close of the TCP connection instead of the expected 221 response code.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.91%
- Percentil entre todas las CVEs puntuadas: 79
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-399, NVD-CWE-noinfo
Referencias
- http://secunia.com/advisories/33142
- http://www.debian.org/security/2008/dsa-1685
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:146
- http://www.openwall.com/lists/oss-security/2008/11/03/5
- http://www.securityfocus.com/bid/32280
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46604
- http://secunia.com/advisories/33142
- http://www.debian.org/security/2008/dsa-1685
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:146
- http://www.openwall.com/lists/oss-security/2008/11/03/5
- http://www.securityfocus.com/bid/32280
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46604
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-5006",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": true,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-11-10T14:12:56.170",
"references": [
{
"url": "http://secunia.com/advisories/33142",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2008/dsa-1685",
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:146",
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/11/03/5",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/32280",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46604",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/33142",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2008/dsa-1685",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:146",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/11/03/5",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/32280",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46604",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-399"
},
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "smtp.c in the c-client library in University of Washington IMAP Toolkit 2007b allows remote SMTP servers to cause a denial of service (NULL pointer dereference and application crash) by responding to the QUIT command with a close of the TCP connection instead of the expected 221 response code."
},
{
"lang": "es",
"value": "smtp.c en la biblioteca c-client en University of Washington IMAP Toolkit 2007b permite a servidores SMTP remotos provocar una denegación de servicio (referencia a puntero NULL y caída de aplicación) por responder al comando QUIT con un cierre de la conexión TCP en lugar de con el código de respuesta 221 esperado."
}
],
"lastModified": "2026-06-16T22:58:56.033",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:university_of_washington:imap_toolkit:2007b:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1AEEC15C-B840-4389-B6CF-F61E4A2244F1"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "The affected code is not used by any application shipped in Red Hat Enterprise Linux 2.1, 3, 4, and 5. The impact of this flaw is limited to a crash of the applications connecting to a misbehaving SMTP server. Due to those reasons, theres currently no plan to include the fix in the imap packages as shipped in Red Hat Enterprise Linux 2.1 and 3, and the libc-client packages as shipped in Red Hat Enterprise Linux 4 and 5.",
"lastModified": "2009-01-30T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}