MailEnable IMAP Service Login Remote Buffer Overflow Vulnerability
BID:21492
Info
MailEnable IMAP Service Login Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 21492 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-6423 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2006 12:00AM |
| Updated: | Feb 16 2007 04:47PM |
| Credit: | Discovered by JJ Reyes, Secunia Research. |
| Vulnerable: |
MailEnable MailEnable Professional 1.7 MailEnable MailEnable Professional 1.6 MailEnable MailEnable Professional 2.35 MailEnable MailEnable Professional 2.34 MailEnable MailEnable Professional 2.33 MailEnable MailEnable Professional 2.32 MailEnable MailEnable Professional 2.2 MailEnable MailEnable Professional 2.1 MailEnable MailEnable Professional 2.0 MailEnable MailEnable Professional 1.84 MailEnable MailEnable Professional 1.83 MailEnable MailEnable Professional 1.82 MailEnable MailEnable Professional 1.73 MailEnable MailEnable Professional 1.72 MailEnable MailEnable Enterprise Edition 1.1 MailEnable MailEnable Enterprise Edition 2.35 MailEnable MailEnable Enterprise Edition 2.34 MailEnable MailEnable Enterprise Edition 2.33 MailEnable MailEnable Enterprise Edition 2.32 MailEnable MailEnable Enterprise Edition 2.2 MailEnable MailEnable Enterprise Edition 2.1 MailEnable MailEnable Enterprise Edition 2.0 MailEnable MailEnable Enterprise Edition 1.41 MailEnable MailEnable Enterprise Edition 1.40 MailEnable MailEnable Enterprise Edition 1.21 MailEnable MailEnable Enterprise Edition 1.2 MailEnable MailEnable Enterprise Edition 1.1 |
| Not Vulnerable: | |
Discussion
MailEnable IMAP Service Login Remote Buffer Overflow Vulnerability
MailEnable is prone to a buffer-overflow vulnerability in the IMAP service because the application fails to properly bounds-check user-supplied input.
This issue is reported to affect the following MailEnable versions, but other versions may also be vulnerable:
1.6-1.84 Professional Edition
1.1-1.41 Enterprise Edition
2.0-2.35 Professional Edition
2.0-2.35 Enterprise Edition
MailEnable is prone to a buffer-overflow vulnerability in the IMAP service because the application fails to properly bounds-check user-supplied input.
This issue is reported to affect the following MailEnable versions, but other versions may also be vulnerable:
1.6-1.84 Professional Edition
1.1-1.41 Enterprise Edition
2.0-2.35 Professional Edition
2.0-2.35 Enterprise Edition
Exploit / POC
MailEnable IMAP Service Login Remote Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
MailEnable IMAP Service Login Remote Buffer Overflow Vulnerability
Solution:
The vendor has released a fix to address this issue. Please see the references for more information.
MailEnable MailEnable Enterprise Edition 2.34
MailEnable MailEnable Professional 2.32
MailEnable MailEnable Professional 2.33
MailEnable MailEnable Enterprise Edition 2.35
MailEnable MailEnable Enterprise Edition 2.0
MailEnable MailEnable Enterprise Edition 1.2
MailEnable MailEnable Enterprise Edition 1.40
MailEnable MailEnable Professional 1.73
MailEnable MailEnable Enterprise Edition 2.1
MailEnable MailEnable Professional 1.72
MailEnable MailEnable Enterprise Edition 2.32
MailEnable MailEnable Professional 1.83
MailEnable MailEnable Professional 1.82
MailEnable MailEnable Enterprise Edition 2.2
MailEnable MailEnable Professional 2.35
MailEnable MailEnable Enterprise Edition 2.33
MailEnable MailEnable Professional 2.34
MailEnable MailEnable Enterprise Edition 1.41
MailEnable MailEnable Professional 2.2
MailEnable MailEnable Professional 2.1
MailEnable MailEnable Professional 1.84
MailEnable MailEnable Enterprise Edition 1.21
MailEnable MailEnable Professional 2.0
MailEnable MailEnable Enterprise Edition 1.1
MailEnable MailEnable Professional 1.6
MailEnable MailEnable Professional 1.7
Solution:
The vendor has released a fix to address this issue. Please see the references for more information.
MailEnable MailEnable Enterprise Edition 2.34
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 2.32
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 2.33
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Enterprise Edition 2.35
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Enterprise Edition 2.0
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Enterprise Edition 1.2
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Enterprise Edition 1.40
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 1.73
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Enterprise Edition 2.1
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 1.72
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Enterprise Edition 2.32
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 1.83
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 1.82
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Enterprise Edition 2.2
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 2.35
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Enterprise Edition 2.33
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 2.34
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Enterprise Edition 1.41
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 2.2
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 2.1
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 1.84
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Enterprise Edition 1.21
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 2.0
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Enterprise Edition 1.1
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 1.6
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
MailEnable MailEnable Professional 1.7
-
MailEnable ME-10025.EXE
http://www.mailenable.com/hotfix/ME-10025.EXE
References
MailEnable IMAP Service Login Remote Buffer Overflow Vulnerability
References:
References:
- MailEnable Homepage (MailEnable)
- MailEnable Hotfix Page (MailEnable)
- Secunia Research: MailEnable IMAP Service Buffer Overflow Vulnerability (Secunia)