CVE Database
/

CVE-2007-5466

Back to search

CVE-2007-5466

Published: Oct 15, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code via a long string in an IMAP AUTHENTICATE PLAIN action, involving the ifParseAuthPlain function; (3) execute arbitrary code via a long LOGIN command to the admin interface port (4501/tcp); or (4) execute arbitrary code via a long string in an IMAP AUTHENTICATE LOGIN (aka CRAM-MD5 authentication) action, involving the ifProcImapAuth1 function.

VendorProductVersions

n/a

n/a

affected
n/a

References

4533
exploit
x_refsource_EXPLOIT-DB
27220
third-party-advisory
x_refsource_SECUNIA
4535
exploit
x_refsource_EXPLOIT-DB
4534
exploit
x_refsource_EXPLOIT-DB
26074
vdb-entry
x_refsource_BID
extremail-crammd5-bo(37209)
vdb-entry
x_refsource_XF
20071015 eXtremail(ly easy) remote roots
mailing-list
x_refsource_BUGTRAQ

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now