CVE-2006-6424
Summary
| CVE | CVE-2006-6424 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-12-27 01:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow; and (2) via crafted arguments to the STOR command to the Network Messaging Application Protocol (NMAP) daemon, resulting in a stack overflow. |
Risk And Classification
Primary CVSS: v2.0 9 from [email protected]
AV:N/AC:L/Au:S/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Novell | Netmail | 3.0.1 | All | All | All |
| Application | Novell | Netmail | 3.0.3a | a | All | All |
| Application | Novell | Netmail | 3.0.3a | b | All | All |
| Application | Novell | Netmail | 3.1 | All | All | All |
| Application | Novell | Netmail | 3.1 | f | All | All |
| Application | Novell | Netmail | 3.10 | All | All | All |
| Application | Novell | Netmail | 3.10 | a | All | All |
| Application | Novell | Netmail | 3.10 | b | All | All |
| Application | Novell | Netmail | 3.10 | c | All | All |
| Application | Novell | Netmail | 3.10 | d | All | All |
| Application | Novell | Netmail | 3.10 | e | All | All |
| Application | Novell | Netmail | 3.10 | f | All | All |
| Application | Novell | Netmail | 3.10 | g | All | All |
| Application | Novell | Netmail | 3.10 | h | All | All |
| Application | Novell | Netmail | 3.5 | All | All | All |
| Application | Novell | Netmail | All | e-ftfl | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| US-CERT Vulnerability Note VU#912505 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| ZDI-06-053 | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | Patch, Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Novell Netmail NMAP STOR Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| US-CERT Vulnerability Note VU#381161 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Security Vulnerabilities: Buffer Overrun in NetMail 3.52 | af854a3a-2127-422b-91ae-364da2661108 | secure-support.novell.com | Patch |
| SecurityReason - Novell NetMail IMAP Verb Literal Heap Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Novell NetMail NMAP/IMAP Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| eCrimeLabs - Helps you mitigate your cyber threats | af854a3a-2127-422b-91ae-364da2661108 | www.cirt.dk | Patch, Vendor Advisory |
| SecurityTracker.com Archives - Novell NetMail Buffer Overflows in IMAP and NMAP Services Let Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Patch |
| Novell Netmail IMAP Verb Literal Heap Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| ZDI-06-052 | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | Patch, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.