PT-2000-1491 · Cmail · Cmail
Published
2000-06-05
·
Updated
2017-10-10
·
CVE-2000-0556
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Cmail version 2.4.7
Description
A buffer overflow issue exists in the web interface, allowing remote attackers to cause a denial of service. This can be achieved by sending a large
username to the user dialog running on port 8002, specifically the / API endpoint is not mentioned but the attack vector is related to the username variable.Recommendations
For Cmail version 2.4.7, consider restricting access to the web interface or limiting the size of the
username variable to prevent exploitation until a fix is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cmail