PT-2005-4561 · Mailenable · Mailenable Professional+1

Josh Zlatin-Amishav

·

Published

2005-11-25

·

Updated

2018-10-19

·

CVE-2005-3813

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions MailEnable Professional versions 1.7 and earlier MailEnable Enterprise versions 1.1 and earlier
Description The issue is related to a denial of service vulnerability in the IMAP service of MailEnable. It occurs when the IMAP server handles the "Rename" command, specifically when attempting to rename non-existent folders. This can cause the service to crash. The estimated number of potentially affected devices is not provided.
Recommendations For MailEnable Professional version 1.7 and earlier, update to a version that fixes this issue. For MailEnable Enterprise version 1.1 and earlier, update to a version that fixes this issue. As a temporary workaround, consider restricting access to the IMAP service or avoiding the use of the "Rename" command with non-existent mailboxes until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3813

Affected Products

Mailenable Enterprise
Mailenable Professional