vendor:
NetMail
by:
MC
N/A
CVSS
N/A
Buffer Overflow
119
CWE
Product Name: NetMail
Affected Version From: 3.52
Affected Version To: 3.52d
Patch Exists: YES
Related CWE: CVE-2006-6761
CPE: a:novell:netmail
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2006
Novell NetMail <= 3.52d IMAP SUBSCRIBE Buffer Overflow
This module exploits a stack buffer overflow in Novell's NetMail 3.52 IMAP SUBSCRIBE verb. By sending an overly long string, an attacker can overwrite the buffer and control program execution.
Mitigation:
Upgrade to the latest version of Novell NetMail