PT-2005-3025 · Ia · Ia Emailserver Corporate Edition

Reed Arvin

·

Published

2005-06-30

·

Updated

2017-07-11

·

CVE-2005-2083

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: IA eMailServer Corporate Edition version 5.2.2 build 1051
Description: The issue is related to a format string vulnerability in the IMAP4 component. This vulnerability can be exploited by remote attackers to cause a denial of service, resulting in an application crash. The exploitation is possible via a LIST command with format string specifiers as the second argument.
Recommendations: For IA eMailServer Corporate Edition version 5.2.2 build 1051, consider restricting access to the IMAP4 component until a fix is available, or avoid using format string specifiers in the LIST command to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2083

Affected Products

Ia Emailserver Corporate Edition