LWN.net Logo

IMP - SQL injection vulnerability

Package(s):imp CVE #(s):CAN-2003-0025
Created:January 15, 2003 Updated:July 8, 2003
Description: The IMP IMAP server, versions 2.2.8 and prior, is vulnerable to SQL injection; see this advisory for details. Version 3.x is not vulnerable to this problem.
Alerts:
Conectiva CLA-2003:690 2003-07-08
SuSE SuSE-SA:2003:0008 2003-02-18
Debian DSA-229-2 2003-01-15

(Log in to post comments)

Re: IMP - SQL injection vulnerability

Posted Feb 1, 2003 2:13 UTC (Sat) by bjn (guest, #2179) [Link]

(1) IMP isn't an IMAP server, it's an IMAP client.

(2) There is now a patch (contributed by a community member) for IMP 2.2.x PostgreSQL sites; it's on www.horde.org in the IMP Contributions section.

(3) We strongly recommend people upgrade to IMP 3.x as soon as possible.

Brent J. Nordquist <bjn@horde.org>

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds