PT-2026-20539 · Unknown · Mailcarrier

Publicado

2026-02-18

·

Atualizado

2026-02-18

·

CVE-2019-25364

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MailCarrier version 2.51
Description MailCarrier 2.51 has a buffer overflow issue in the POP3 USER command. Remote attackers can exploit this by sending a specially crafted, oversized buffer to the POP3 service. This can overwrite memory and potentially allow for remote system access. The vulnerable command is POP3 USER. The vulnerable parameter is the buffer sent with the USER command.
Recommendations Update MailCarrier to a version that addresses this issue. As a temporary workaround, consider disabling the POP3 service if it is not essential.

Exploit

Correção

Stack Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-25364

Produtos afetados

Mailcarrier