PT-2006-5184 · Ipswitch · Imail+3

Published

2006-09-08

·

Updated

2018-10-17

·

CVE-2006-4379

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ipswitch Collaboration 2006 Suite Premium and Standard Editions (affected versions not specified) IMail (affected versions not specified) IMail Plus (affected versions not specified) IMail Secure (affected versions not specified)
Description The issue is a stack-based buffer overflow in the SMTP Daemon. It allows remote attackers to execute arbitrary code via a long string located after an '@' character and before a ':' character.
Recommendations For Ipswitch Collaboration 2006 Suite Premium and Standard Editions, update to a version that fixes the SMTP Daemon issue. For IMail, update to a version that fixes the SMTP Daemon issue. For IMail Plus, update to a version that fixes the SMTP Daemon issue. For IMail Secure, update to a version that fixes the SMTP Daemon issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4379

Affected Products

Imail
Imail Plus
Imail Secure
Ipswitch Collaboration 2006 Suite