Vulnerability record · CVE-2005-4267 · published 21 December 2005
CVE-2005-4267: Qualcomm WorldMail IMAP stack buffer overflow via long commands
Qualcomm · Worldmail
Qualcomm WorldMail 3.0 contains a stack-based buffer overflow in its IMAP service. A remote attacker can send an overly long IMAP command ending in a "}" character to overwrite stack memory and potentially execute arbitrary code. The flaw is remotely reachable and requires no authentication, making it a serious pre-auth risk for exposed mail servers.
Description
Stack-based buffer overflow in Qualcomm WorldMail 3.0 allows remote attackers to execute arbitrary code via a long IMAP command that ends with a "}" character, as demonstrated using long (1) LIST, (2) LSUB, (3) SEARCH TEXT, (4) STATUS INBOX, (5) AUTHENTICATE, (6) FETCH, (7) SELECT, and (8) COPY commands.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw is a remotely reachable, unauthenticated stack buffer overflow with public exploit references and very high EPSS, though it is not in KEV and affects an old product.
What it is
Qualcomm WorldMail 3.0 contains a stack-based buffer overflow in its IMAP service. A remote attacker can send an overly long IMAP command ending in a "}" character to overwrite stack memory and potentially execute arbitrary code. The flaw is remotely reachable and requires no authentication, making it a serious pre-auth risk for exposed mail servers.
Impact
An attacker can corrupt stack memory and potentially execute arbitrary code with the privileges of the WorldMail IMAP service. Successful exploitation could lead to full compromise of the mail server host.
Attack surface
The flaw is reached over the network through the IMAP service by sending crafted long commands such as LIST, LSUB, SEARCH TEXT, STATUS INBOX, AUTHENTICATE, FETCH, SELECT, or COPY. The CVSS vector AV:N/AC:L/Au:N indicates no authentication is required and no user interaction is needed.
Exploitation
CVE-2005-4267 is not listed in CISA KEV, but public references are tagged Exploit, indicating proof-of-concept or exploit code is publicly available. EPSS shows a 30-day probability of 0.66803 (99.256th percentile), suggesting high predicted exploitation activity.
What to do
- Apply the vendor patch or upgrade Qualcomm WorldMail to a fixed version if one is available; the record does not specify affected or fixed versions.
- Restrict network access to the IMAP service to trusted hosts only, and block IMAP from the public internet where possible.
- Place the IMAP service behind a filtering proxy or intrusion prevention system that can drop malformed or oversized IMAP commands.
- Monitor vendor and security advisories for WorldMail 3.0 since the record does not list a confirmed fixed release.
- If the product is end-of-life and no patch exists, migrate to a supported mail server or isolate the service on a segmented network.
Detection
- Inspect IMAP server logs for unusually long commands or commands ending with a "}" character, especially LIST, LSUB, SEARCH TEXT, STATUS INBOX, AUTHENTICATE, FETCH, SELECT, and COPY.
- Monitor for crashes, restarts, or abnormal process termination of the WorldMail IMAP service.
- Use network IDS/IPS signatures for oversized IMAP commands and known exploit patterns against WorldMail.
- Alert on unexpected outbound connections or child processes spawned by the IMAP service, which may indicate code execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://seclists.org/lists/fulldisclosure/2005/Dec/1037.html | ExploitVendor Advisory |
| http://secunia.com/advisories/17640 | Vendor Advisory |
| http://securityreason.com/securityalert/277 | |
| http://securitytracker.com/id?1015391 | |
| http://www.idefense.com/intelligence/vulnerabilities/display.php?id=359 | Vendor Advisory |
| http://www.securityfocus.com/bid/15980 | Exploit |
| http://www.vupen.com/english/advisories/2005/3005 | Vendor Advisory |
| http://seclists.org/lists/fulldisclosure/2005/Dec/1037.html | ExploitVendor Advisory |
| http://secunia.com/advisories/17640 | Vendor Advisory |
| http://securityreason.com/securityalert/277 | |
| http://securitytracker.com/id?1015391 | |
| http://www.idefense.com/intelligence/vulnerabilities/display.php?id=359 | Vendor Advisory |
| http://www.securityfocus.com/bid/15980 | Exploit |
| http://www.vupen.com/english/advisories/2005/3005 | Vendor Advisory |
Track CVE-2005-4267 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-4267), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.