PT-2005-2265 · Ipswitch · Ipswitch Imail
Published
2005-05-25
·
Updated
2008-11-15
·
CVE-2005-1255
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Ipswitch IMail versions prior to 8.2 Hotfix 2
Description:
The issue concerns multiple stack-based buffer overflows in the IMAP server. These overflows can be triggered by remote attackers via a LOGIN command with either a long
username argument or a username that begins with a special character, potentially allowing the execution of arbitrary code.Recommendations:
For Ipswitch IMail versions prior to 8.2 Hotfix 2, update to version 8.2 Hotfix 2 or later to resolve the issue. As a temporary workaround, consider restricting access to the IMAP server or limiting the length of
username arguments in the LOGIN command to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ipswitch Imail