PT-2005-1112 · Ipswitch · Ipswitch Imail

Published

2005-05-02

·

Updated

2017-12-19

·

CVE-1999-1557

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Ipswitch IMail versions 5.0 and earlier
Description The issue is related to a buffer overflow in the login functions of the IMAP server, which can be triggered by a remote attacker using either a long user name or a long password. This can cause a denial of service and potentially allow the execution of arbitrary code.
Recommendations For Ipswitch IMail versions 5.0 and earlier, consider updating to a version later than 5.0 to resolve the issue. As a temporary workaround, restrict access to the IMAP server to minimize the risk of exploitation. Avoid using long user names or passwords in the affected login functions until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1557

Affected Products

Ipswitch Imail