PT-2004-3617 · Mailenable · Mailenable Professional

Published

2004-12-31

·

Updated

2017-07-29

·

CVE-2004-2727

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions MailEnable Professional versions 1.5 through 1.7
Description The issue is related to a buffer overflow in the MEHTTPS (HTTPMail) component, which can be triggered by a long HTTP GET request. This can cause a denial of service, resulting in an application crash.
Recommendations For MailEnable Professional versions 1.5 through 1.7, consider restricting access to the MEHTTPS component until a patch is available. As a temporary workaround, limit the length of HTTP GET requests to prevent the buffer overflow.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-2727

Affected Products

Mailenable Professional