PT-2004-3616 · Mailenable · Mailenable Professional

Oliver Karow

·

Published

2004-12-31

·

Updated

2008-09-05

·

CVE-2004-2726

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions MailEnable Professional version 1.18
Description The HTTPMail service in MailEnable Professional does not properly handle arguments to the Authorization header, allowing remote attackers to cause a denial of service, resulting in a null dereference and application crash.
Recommendations For MailEnable Professional version 1.18, consider restricting access to the Authorization header until a patch is available. As a temporary workaround, disabling the HTTPMail service may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2726

Affected Products

Mailenable Professional