CVE-1999-1046: Buffer Overflow
Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Stop or disable the IMonitor service so it no longer listens on port 8181 until a vendor fix is available.
Ipswitch IMail (IMonitor) IMonitor service/listener = disabled/stopped - Compensating control
Block or restrict access to TCP port 8181 (IMonitor) at network firewalls and host-based firewalls/ACLs to prevent remote attackers from sending long strings to the service.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1046?
CVE-1999-1046 has a high severity due to the potential for remote code execution and denial of service.
How do I fix CVE-1999-1046?
To mitigate CVE-1999-1046, upgrade to a version of IMail that is not vulnerable to buffer overflow issues.
What systems are affected by CVE-1999-1046?
CVE-1999-1046 specifically affects IPSwitch IMail version 5.0.
What type of vulnerability is CVE-1999-1046?
CVE-1999-1046 is a buffer overflow vulnerability that can lead to remote attacks.
What can attackers achieve with CVE-1999-1046?
With CVE-1999-1046, attackers can cause a denial of service and potentially execute arbitrary commands.