PT-2007-5147 · Ipswitch · Ipswitch Imail Server
Published
2007-07-21
·
Updated
2017-07-29
·
CVE-2007-3927
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Ipswitch IMail Server 2006 versions prior to 2006.21
Description:
The issue involves multiple buffer overflows that can be exploited by remote attackers to execute arbitrary code. This is achieved through unspecified vectors in Imailsec. Additionally, there is an unspecified vector related to "subscribe" that can have an unknown impact.
Recommendations:
For Ipswitch IMail Server 2006 versions prior to 2006.21, update to version 2006.21 or later to resolve the issue. As a temporary workaround, consider restricting access to the Imailsec component and limiting the use of the "subscribe" functionality until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ipswitch Imail Server