MailEnable Enterprise/Professional Editions Webmail Denial of Service Vulnerability
BID:17161
Info
MailEnable Enterprise/Professional Editions Webmail Denial of Service Vulnerability
| Bugtraq ID: | 17161 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2006 12:00AM |
| Updated: | Mar 21 2006 04:24PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
MailEnable MailEnable Professional 1.116 MailEnable MailEnable Professional 1.115 MailEnable MailEnable Professional 1.114 MailEnable MailEnable Professional 1.113 MailEnable MailEnable Professional 1.112 MailEnable MailEnable Professional 1.111 MailEnable MailEnable Professional 1.110 MailEnable MailEnable Professional 1.109 MailEnable MailEnable Professional 1.108 MailEnable MailEnable Professional 1.107 MailEnable MailEnable Professional 1.106 MailEnable MailEnable Professional 1.105 MailEnable MailEnable Professional 1.104 MailEnable MailEnable Professional 1.103 MailEnable MailEnable Professional 1.102 MailEnable MailEnable Professional 1.101 MailEnable MailEnable Professional 1.54 MailEnable MailEnable Professional 1.53 MailEnable MailEnable Professional 1.52 MailEnable MailEnable Professional 1.51 MailEnable MailEnable Professional 1.19 MailEnable MailEnable Professional 1.19 MailEnable MailEnable Professional 1.18 MailEnable MailEnable Professional 1.18 MailEnable MailEnable Professional 1.17 MailEnable MailEnable Professional 1.17 MailEnable MailEnable Professional 1.16 MailEnable MailEnable Professional 1.16 MailEnable MailEnable Professional 1.15 MailEnable MailEnable Professional 1.14 MailEnable MailEnable Professional 1.13 MailEnable MailEnable Professional 1.12 MailEnable MailEnable Professional 1.7 MailEnable MailEnable Professional 1.6 MailEnable MailEnable Professional 1.5 MailEnable MailEnable Professional 1.2 a MailEnable MailEnable Professional 1.2 a MailEnable MailEnable Professional 1.2 MailEnable MailEnable Professional 1.2 MailEnable MailEnable Professional 1.1 MailEnable MailEnable Professional 1.0 017 MailEnable MailEnable Professional 1.0 016 MailEnable MailEnable Professional 1.0 015 MailEnable MailEnable Professional 1.0 014 MailEnable MailEnable Professional 1.0 013 MailEnable MailEnable Professional 1.0 012 MailEnable MailEnable Professional 1.0 011 MailEnable MailEnable Professional 1.0 010 MailEnable MailEnable Professional 1.0 009 MailEnable MailEnable Professional 1.0 008 MailEnable MailEnable Professional 1.0 007 MailEnable MailEnable Professional 1.0 006 MailEnable MailEnable Professional 1.0 005 MailEnable MailEnable Professional 1.0 004 MailEnable MailEnable Professional 1.72 MailEnable MailEnable Enterprise Edition 1.1 MailEnable MailEnable Enterprise Edition 1.0 4 MailEnable MailEnable Enterprise Edition 1.0 3 MailEnable MailEnable Enterprise Edition 1.0 2 MailEnable MailEnable Enterprise Edition 1.0 1 MailEnable MailEnable Enterprise Edition 1.0 MailEnable MailEnable Enterprise Edition 1.2 |
| Not Vulnerable: |
MailEnable MailEnable Professional 1.73 MailEnable MailEnable Enterprise Edition 1.21 |
Discussion
MailEnable Enterprise/Professional Editions Webmail Denial of Service Vulnerability
MailEnable Enterprise/Professional Editions are prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the application to consume all available resources, effectively denying service to legitimate users.
This issue is reported to be a seperate issue from that discussed in BID 16525 (MailEnable Enterprise Edition Webmail Denial of Service Vulnerability).
MailEnable Enterprise/Professional Editions are prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the application to consume all available resources, effectively denying service to legitimate users.
This issue is reported to be a seperate issue from that discussed in BID 16525 (MailEnable Enterprise Edition Webmail Denial of Service Vulnerability).
Exploit / POC
MailEnable Enterprise/Professional Editions Webmail Denial of Service Vulnerability
This issue can be exploited by constructing a specially formated 'quoted-printable' email message.
This issue can be exploited by constructing a specially formated 'quoted-printable' email message.
Solution / Fix
MailEnable Enterprise/Professional Editions Webmail Denial of Service Vulnerability
Solution:
The vendor has released updates to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
The vendor has released updates to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
References
MailEnable Enterprise/Professional Editions Webmail Denial of Service Vulnerability
References:
References:
- MailEnable - Enterprise Edition Revision History (MailEnable)
- MailEnable Homepage (MailEnable)
- MailEnable Professional History (MailEnable)