PT-2004-3616 · Mailenable · Mailenable Professional
Oliver Karow
·
Published
2004-12-31
·
Updated
2008-09-05
·
CVE-2004-2726
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
MailEnable Professional version 1.18
Description
The HTTPMail service in MailEnable Professional does not properly handle arguments to the
Authorization header, allowing remote attackers to cause a denial of service, resulting in a null dereference and application crash.Recommendations
For MailEnable Professional version 1.18, consider restricting access to the
Authorization header until a patch is available. As a temporary workaround, disabling the HTTPMail service may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mailenable Professional