This script is Copyright (C) 2005-2011 Tenable Network Security, Inc.
The remote mail server is affected by multiple issues.
GNU Mailutils is a collection of mail utilities, including an IMAP4
daemon, a POP3 daemon, and a very simple mail client.
The remote host is running a version of GNU Mailutils containing
several critical flaws in its IMAP4 daemon and its mail client 'mail'.
By exploiting these issues, a remote attacker can cause a denial of
service in the IMAP4 daemon and execute code remotely, either in the
context of a local user or the user executing the daemon process,
In addition, it may suffer from a SQL injection flaw if configured to
work with MySQL or Postgres. An attacker may be able to exploit this
flaw to modify database queries when mailutils tries to authenticate a
user, leading to disclosure of sensitive information or modification
See also :
Upgrade to GNU Mailutils 0.6.90 or later.
Risk factor :
High / CVSS Base Score : 7.5
CVSS Temporal Score : 5.5
Public Exploit Available : false
Family: Gain a shell remotely
Nessus Plugin ID: 18371 (gnu_mailutils_060.nasl)
Bugtraq ID: 1376313764137651376613870
CVE ID: CVE-2005-1520CVE-2005-1521CVE-2005-1522CVE-2005-1523CVE-2005-1824
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.