vendor:
IMail Server
by:
Rootshell
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: IMail Server
Affected Version From: 2.71 SP1
Affected Version To: 2.71 SP1
Patch Exists: YES
Related CWE: N/A
CPE: 2.7:a:ipswitch:imail_server:2.71_sp1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
1998
Ipswitch IMail Server SMTP HELO Command Argument Buffer Overflow Vulnerability
It has been reported that Ipswitch IMail server is prone to an SMTP HELO command argument buffer overflow vulnerability. The issue presents itself likely due to insufficient bounds checking performed when handling malicious SMTP HELO command arguments of excessive length. It has been reported that a remote attacker may exploit this condition to trigger a denial of service in the affected daemon.
Mitigation:
Apply the latest security patches and ensure that all user input is validated.