---
title: "CVE-2008-5005\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2008-5005?format=md
keywords: index, follow
---

# CVE-2008-5005

Publication date 10 November 2008

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Multiple stack-based buffer overflows in (1) University of Washington IMAP
Toolkit 2002 through 2007c, (2) University of Washington Alpine 2.00 and
earlier, and (3) Panda IMAP allow (a) local users to gain privileges by
specifying a long folder extension argument on the command line to the
tmail or dmail program; and (b) remote attackers to execute arbitrary code
by sending e-mail to a destination mailbox name composed of a username and
'+' character followed by a long string, processed by the tmail or possibly
dmail program.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2008-5005?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| alpine | 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 9.10 karmic | Not affected |
| 9.04 jaunty | Not affected |
| 8.10 intrepid | Not affected |
| 8.04 LTS hardy | Not affected |
| 7.10 gutsy | Ignored end of life, was needed |
| 6.06 LTS dapper | Not in release |
| uw-imap | 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 9.10 karmic | Not affected |
| 9.04 jaunty | Not affected |
| 8.10 intrepid | Ignored end of life, was needed |
| 8.04 LTS hardy | Ignored end of life |
| 7.10 gutsy | Ignored end of life, was needed |
| 6.06 LTS dapper | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

per debian, alpine isn't vulnerable

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5005)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2008-5005)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2008-5005)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2008-5005)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2008-5005>
