PT-2007-2750 · Novell · Novell Netmail
Published
2007-03-08
·
Updated
2018-10-16
·
CVE-2007-1350
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Novell NetMail version 3.5.2
Description
The issue is a stack-based buffer overflow in the webadmin.exe component. It allows remote attackers to execute arbitrary code by providing a long
username during HTTP Basic authentication.Recommendations
For Novell NetMail version 3.5.2, consider disabling HTTP Basic authentication until a patch is available to prevent exploitation. Restrict access to the webadmin.exe component to minimize the risk of arbitrary code execution. Avoid using long usernames in the authentication process until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Novell Netmail