WinWebMail IMAP Login Data Handling Denial Of Service Vulnerability
BID:28721
Info
WinWebMail IMAP Login Data Handling Denial Of Service Vulnerability
| Bugtraq ID: | 28721 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2008 12:00AM |
| Updated: | Apr 16 2008 12:29AM |
| Credit: | Matteo Memelli <[email protected]> |
| Vulnerable: |
WinWebMail WinWebMail 3.7.3 .2 |
| Not Vulnerable: | |
Discussion
WinWebMail IMAP Login Data Handling Denial Of Service Vulnerability
WinWebMail is prone to a denial-of-service vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Remote attackers can exploit this issue to crash the server and deny service to legitimate users. Given the nature of this issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.
WinWebMail 3.7.3.2 is vulnerable; other versions may also be affected.
WinWebMail is prone to a denial-of-service vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Remote attackers can exploit this issue to crash the server and deny service to legitimate users. Given the nature of this issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.
WinWebMail 3.7.3.2 is vulnerable; other versions may also be affected.
Exploit / POC
WinWebMail IMAP Login Data Handling Denial Of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
WinWebMail IMAP Login Data Handling Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WinWebMail IMAP Login Data Handling Denial Of Service Vulnerability
References:
References:
- Vendor Homepage (WinWebMail)