PT-2007-2329 · Axigen · Axigen

Mu-B

·

Publicado

2007-02-12

·

Atualizado

2017-10-19

·

CVE-2007-0887

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: axigen versions 1.2.6 through 2.0.0b1
Description: The issue is related to improper parsing of login credentials, which can be exploited by remote attackers to cause a denial of service. This is achieved by sending a base64-encoded "*x00" sequence on the imap port (143/tcp), resulting in a NULL dereference and application crash.
Recommendations: For axigen versions 1.2.6 through 2.0.0b1, consider restricting access to the imap port (143/tcp) as a temporary workaround until a patch is available. Avoid using base64-encoded sequences that contain null characters (x00) in login credentials to minimize the risk of exploitation.

Exploit

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-0887

Produtos afetados

Axigen