Vulnerability Description
Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code via a long string in an IMAP AUTHENTICATE PLAIN action, involving the ifParseAuthPlain function; (3) execute arbitrary code via a long LOGIN command to the admin interface port (4501/tcp); or (4) execute arbitrary code via a long string in an IMAP AUTHENTICATE LOGIN (aka CRAM-MD5 authentication) action, involving the ifProcImapAuth1 function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Extremail | Extremail | <= 2.1.1 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/27220Vendor Advisory
- http://www.digit-labs.org/files/exploits/extremail-v4.c
- http://www.digit-labs.org/files/exploits/extremail-v5.c
- http://www.digit-labs.org/files/exploits/extremail-v6.c
- http://www.digit-labs.org/files/exploits/extremail-v8.pl
- http://www.securityfocus.com/archive/1/482293
- http://www.securityfocus.com/bid/26074
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37209
- https://www.exploit-db.com/exploits/4533
- https://www.exploit-db.com/exploits/4534
- https://www.exploit-db.com/exploits/4535
- http://secunia.com/advisories/27220Vendor Advisory
- http://www.digit-labs.org/files/exploits/extremail-v4.c
- http://www.digit-labs.org/files/exploits/extremail-v5.c
- http://www.digit-labs.org/files/exploits/extremail-v6.c
FAQ
What is CVE-2007-5466?
CVE-2007-5466 is a vulnerability with a CVSS score of 10.0 (HIGH). Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code vi...
How severe is CVE-2007-5466?
CVE-2007-5466 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5466?
Check the references section above for vendor advisories and patch information. Affected products include: Extremail Extremail.