"Multiple buffer overflow vulnerabilities have been identified in Courier MTA, Courier SqWebMail, and Courier-IMAP. These vulnerabilities may allow a remote attacker to execute arbitrary code on a vulnerable system in order to gain unauthorized access." Source : http://www.securityfocus.com/bid/9845/info/ Where I can found patch for cobalt RaQ4
I'm not saying that the Raq4 isn't vulnerable but it doesn't use any of these IMAP servers it uses the "University of Washington IMAP toolkit".
Regards, Dan -- http://www.dogsbody.org/