|
|
Vulnerability Assessment & Network Security Forums |
|||||||||
|
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> Gain a shell remotely >> MailEnable IMAP Overflow and SMTP Vulnerabilities Vulnerability Assessment Details
|
MailEnable IMAP Overflow and SMTP Vulnerabilities |
||
|
Checks for IMAP overflow and SMTP DoS vulnerabilities in MailEnable Detailed Explanation for this Vulnerability Assessment Summary : The remote mail server is affected by multiple issues. Description : The remote host is running a version of MailEnable Professional or MailEnable Enterprise Edition that is prone to the following vulnerabilities: - An IMAP Authenticate Request Buffer Overflow Vulnerability Sending an AUTHENTICATE or LOGIN command with an argument of 1016 characters or more overflows a stack-based buffer. A possible hacker can leverage this flaw to overwrite sensitive program control variables and thereby control execution flow of the server process. - An SMTP Malformed EHLO Request Denial Of Service Vulnerability The SMTP service does not properly handle malformed EHLO commands and may crash when it encounters an argument containing the character 0x99. A remote attacker could use this flaw to crash the SMTP service, thereby denying service to legitimate users. See also : http://archives.neohapsis.com/archives/bugtraq/2005-04/0070.html http://archives.neohapsis.com/archives/fulldisclosure/2005-04/0078.html Solution : Apply the IMAP and SMTP hotfix from 4th April 2005 located at http://www.mailenable.com/hotfix/. [Note that this does not fix the overflow involving an oversize LOGIN command.] Network Security Threat Level: Critical / CVSS Base Score : 10 (AV:R/AC:L/Au:NR/C:C/A:C/I:C/B:N) Networks Security ID: 12994, 12995, 13040 Vulnerability Assessment Copyright: This script is Copyright (C) 2005-2007 Tenable Network Security |
||
|
Cables, Connectors |

Lenovo ThinkPad E14 Gen 2 Laptop 14” HD Ryzen 5 16GB RAM 512GB SSD Win 11 Pro
$334.99
Lenovo ThinkPad L15 Gen 3 15.6" 16GB, Thunder Black
$241.50
Lenovo Thinkbook 14s Yoga ITL 14” Core i7-1165G7, 16GB RAM, 512GB SSD Touch
$379.00
Lenovo ThinkPad E14 Gen 3 Laptop 14” FHD AMD Ryzen 5 16GB RAM 512GB SSD Win 11
$374.99
Lenovo Legion 5 Gaming 15.1" WQXGA OLED 165Hz Core i9-14900HX 16GB 1TB RTX 5070
$1469.00
Lenovo ThinkPad T14 Gen 1 14" AMD Ryzen 5 16GB 256GB SSD
$219.99
Lenovo ThinkPad X13 Gen 1 i5-10310U 16GB 512GB SSD Touch Win 11 Pro Good
$222.99
Lenovo - IdeaPad Slim 3i 15.3" 2K Touchscreen Laptop - Intel Core 7 350 2026 ...
$679.99
Lenovo ThinkPad L15 Gen 3 15.6" 16GB, Thunder Black
$241.50
Lenovo ThinkPad T14s Laptop 14” Laptop Core i5 8GB RAM 256GB SSD Windows 11 Pro
$249.99
|
||
|
No Discussions have been posted on this vulnerability. |