PT-2005-1112 · Ipswitch · Ipswitch Imail
Published
2005-05-02
·
Updated
2017-12-19
·
CVE-1999-1557
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Ipswitch IMail versions 5.0 and earlier
Description
The issue is related to a buffer overflow in the login functions of the IMAP server, which can be triggered by a remote attacker using either a long user name or a long password. This can cause a denial of service and potentially allow the execution of arbitrary code.
Recommendations
For Ipswitch IMail versions 5.0 and earlier, consider updating to a version later than 5.0 to resolve the issue. As a temporary workaround, restrict access to the IMAP server to minimize the risk of exploitation. Avoid using long user names or passwords in the affected login functions until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ipswitch Imail