PT-2006-5184 · Ipswitch · Imail+3
Published
2006-09-08
·
Updated
2018-10-17
·
CVE-2006-4379
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ipswitch Collaboration 2006 Suite Premium and Standard Editions (affected versions not specified)
IMail (affected versions not specified)
IMail Plus (affected versions not specified)
IMail Secure (affected versions not specified)
Description
The issue is a stack-based buffer overflow in the SMTP Daemon. It allows remote attackers to execute arbitrary code via a long string located after an '@' character and before a ':' character.
Recommendations
For Ipswitch Collaboration 2006 Suite Premium and Standard Editions, update to a version that fixes the SMTP Daemon issue.
For IMail, update to a version that fixes the SMTP Daemon issue.
For IMail Plus, update to a version that fixes the SMTP Daemon issue.
For IMail Secure, update to a version that fixes the SMTP Daemon issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Imail
Imail Plus
Imail Secure
Ipswitch Collaboration 2006 Suite