PT-2004-3616 · Mailenable · Mailenable Professional

Oliver Karow

·

Publicado

2004-12-31

·

Atualizado

2008-09-05

·

CVE-2004-2726

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions MailEnable Professional version 1.18
Description The HTTPMail service in MailEnable Professional does not properly handle arguments to the Authorization header, allowing remote attackers to cause a denial of service, resulting in a null dereference and application crash.
Recommendations For MailEnable Professional version 1.18, consider restricting access to the Authorization header until a patch is available. As a temporary workaround, disabling the HTTPMail service may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-2726

Produtos afetados

Mailenable Professional