CVE-2000-0239: Buffer Overflow
Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mailuser parameter in the GET request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
MERCUR WebView WebMail serverfrom your environment.Uninstall or remove the MERCUR WebView WebMail server component if it is not required.
- Configuration
Disable the MERCUR WebView WebMail server to prevent remote exploitation via a long mail_user parameter in GET requests.
MERCUR WebView WebMail server enabled = false - Compensating control
Block or restrict HTTP access to the MERCUR WebView WebMail interface at the network perimeter (firewall/ACL) or deploy a WAF rule to drop requests with overly long mail_user parameters to mitigate the buffer overflow.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0239?
CVE-2000-0239 is considered a critical vulnerability due to its potential to cause denial of service through a buffer overflow.
How do I fix CVE-2000-0239?
To fix CVE-2000-0239, users should upgrade to a patched version of the software that resolves this buffer overflow issue.
Which software versions are affected by CVE-2000-0239?
CVE-2000-0239 affects Atrium Software Mercur Mailserver 3.2 and Mercur POP3 and IMAP4 servers version 3.20.01.
Can CVE-2000-0239 be exploited remotely?
Yes, CVE-2000-0239 can be exploited remotely by sending specially crafted GET requests.
What types of attacks can be executed using CVE-2000-0239?
Exploitation of CVE-2000-0239 can lead to denial of service attacks, disrupting service availability.