vendor:
MailEnable Professional HTTPMail
by:
CoolICE
7.5
CVSS
HIGH
Remote Denial of Service
CWE
Product Name: MailEnable Professional HTTPMail
Affected Version From: MailEnable Professional HTTPMail 1.19
Affected Version To: MailEnable Professional HTTPMail 1.19
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2004
MailEnable Remote Denial of Service Vulnerability
MailEnable is prone to a remote denial of service vulnerability. This vulnerability exists in the MailEnable HTTP header parsing code. When reading a large content-length header field from an HTTP request, the operation overflows a fixed-size memory buffer, causing the HTTP service to crash. The vulnerability can be exploited to crash the affected HTTP service, denying service to legitimate users. There is also a possibility to execute arbitrary code.