PT-2004-3617 · Mailenable · Mailenable Professional
Publicado
2004-12-31
·
Atualizado
2017-07-29
·
CVE-2004-2727
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
MailEnable Professional versions 1.5 through 1.7
Description
The issue is related to a buffer overflow in the MEHTTPS (HTTPMail) component, which can be triggered by a long HTTP GET request. This can cause a denial of service, resulting in an application crash.
Recommendations
For MailEnable Professional versions 1.5 through 1.7, consider restricting access to the MEHTTPS component until a patch is available. As a temporary workaround, limit the length of HTTP GET requests to prevent the buffer overflow.
Exploit
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mailenable Professional