PT-2007-5558 · Netwin · Surgemail

Joey Mengele

·

Published

2007-08-16

·

Updated

2017-10-19

·

CVE-2007-4377

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SurgeMail version 38k
Description The issue is related to a stack-based buffer overflow in the IMAP service, allowing remote authenticated users to execute arbitrary code by providing a long argument to the SEARCH command.
Recommendations For SurgeMail version 38k, consider disabling the IMAP service until a patch is available to prevent potential exploitation. Restrict access to the SEARCH command to minimize the risk of arbitrary code execution.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4377

Affected Products

Surgemail