PT-2026-20539 · Unknown · Mailcarrier
Publicado
2026-02-18
·
Atualizado
2026-02-18
·
CVE-2019-25364
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MailCarrier version 2.51
Description
MailCarrier 2.51 has a buffer overflow issue in the POP3
USER command. Remote attackers can exploit this by sending a specially crafted, oversized buffer to the POP3 service. This can overwrite memory and potentially allow for remote system access. The vulnerable command is POP3 USER. The vulnerable parameter is the buffer sent with the USER command.Recommendations
Update MailCarrier to a version that addresses this issue. As a temporary workaround, consider disabling the POP3 service if it is not essential.
Exploit
Correção
Stack Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mailcarrier