PT-2005-2265 · Ipswitch · Ipswitch Imail

Published

2005-05-25

·

Updated

2008-11-15

·

CVE-2005-1255

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Ipswitch IMail versions prior to 8.2 Hotfix 2
Description: The issue concerns multiple stack-based buffer overflows in the IMAP server. These overflows can be triggered by remote attackers via a LOGIN command with either a long username argument or a username that begins with a special character, potentially allowing the execution of arbitrary code.
Recommendations: For Ipswitch IMail versions prior to 8.2 Hotfix 2, update to version 8.2 Hotfix 2 or later to resolve the issue. As a temporary workaround, consider restricting access to the IMAP server or limiting the length of username arguments in the LOGIN command to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1255

Affected Products

Ipswitch Imail