PT-2007-5558 · Netwin · Surgemail
Joey Mengele
·
Published
2007-08-16
·
Updated
2017-10-19
·
CVE-2007-4377
CVSS v2.0
6.0
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SurgeMail version 38k
Description
The issue is related to a stack-based buffer overflow in the IMAP service, allowing remote authenticated users to execute arbitrary code by providing a long argument to the
SEARCH command.Recommendations
For SurgeMail version 38k, consider disabling the IMAP service until a patch is available to prevent potential exploitation. Restrict access to the
SEARCH command to minimize the risk of arbitrary code execution.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Surgemail