PT-2006-4901 · Eremove · Eremove
Dedi Dwianto
·
Published
2006-08-10
·
Updated
2018-10-17
·
CVE-2006-4057
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Eremove version 1.4
Description
The issue is related to a buffer overflow in the
preview create function, which can be triggered by a large email attachment. This can cause a denial of service, resulting in an application crash, and potentially allow the execution of arbitrary code.Recommendations
For Eremove version 1.4, consider disabling the
preview create function in gui.cpp to prevent potential exploitation until a fix is available. Restrict the handling of large email attachments to minimize the risk of a denial of service or code execution.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eremove