PT-2006-7207 · Mailenable · Mailenable Standard+2

Carsten Eiram

·

Publicado

2006-12-19

·

Atualizado

2018-10-17

·

CVE-2006-6605

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MailEnable Standard versions 1.98 and earlier MailEnable Professional versions 1.84 and 2.35 and earlier MailEnable Enterprise versions 1.41 and 2.35 and earlier
Description The issue is caused by a boundary error in the POP service when handling arguments passed to the PASS command, leading to a stack-based buffer overflow. This can be exploited by passing an overly long, specially crafted string as an argument to the affected command, allowing execution of arbitrary code.
Recommendations For MailEnable Standard versions 1.98 and earlier, update to a version later than 1.98. For MailEnable Professional versions 1.84 and 2.35 and earlier, update to a version later than 2.35. For MailEnable Enterprise versions 1.41 and 2.35 and earlier, update to a version later than 2.35. As a temporary workaround, consider restricting access to the POP service until a patch is available. Avoid using the PASS command with long arguments in the affected MailEnable versions to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6605

Produtos afetados

Mailenable Enterprise
Mailenable Professional
Mailenable Standard