PT-2006-3832 · Qbik · Wingate

Publicado

2006-07-10

·

Atualizado

2011-03-08

·

CVE-2006-2917

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions WinGate versions 6.1.2.1094 through 6.1.3.1096 WinGate versions prior to 6.1.4 Build 1099
Description The issue allows remote authenticated users to perform unauthorized operations, such as reading email of other users or modifying directories, by exploiting a directory traversal vulnerability in the IMAP server. This can be achieved via various IMAP commands, including CREATE, SELECT, DELETE, RENAME, COPY, APPEND, and LIST.
Recommendations For WinGate versions 6.1.2.1094 through 6.1.3.1096, update to version 6.1.4 Build 1099 or later. For WinGate versions prior to 6.1.4 Build 1099, update to version 6.1.4 Build 1099 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2917

Produtos afetados

Wingate