vendor:
Merak Mail Server
by:
Nine:Situations:Group::surfista
9,3
CVSS
HIGH
Stack Based Buffer Overflow
119
CWE
Product Name: Merak Mail Server
Affected Version From: 9.4.1
Affected Version To: 9.4.1
Patch Exists: YES
Related CWE: N/A
CPE: a:icewarp:merak_mail_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Icewarp Merak Mail Server 9.4.1 IceWarpServer.APIObject/api.dll Base64FileEncode() stack based buffer overflow poc
Icewarp Merak Mail Server 9.4.1 contains a stack based buffer overflow vulnerability in the second argument of Base64FileEncode() method, which can be exploited by a remote user to execute arbitrary code.
Mitigation:
Upgrade to the latest version of Icewarp Merak Mail Server.