CVE-2000-0239: Buffer Overflow

Published Mar 15, 2000
·
Updated

Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mailuser parameter in the GET request.

Affected Software

3 affected components
Atrium Software Mercur Pop3 Server=3.20.01
Atrium Software Mercur Mailserver=3.2
Atrium Software Mercur Imap4 Server=3.20.01

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove MERCUR WebView WebMail server from your environment.

    Uninstall or remove the MERCUR WebView WebMail server component if it is not required.

  2. Configuration

    Disable the MERCUR WebView WebMail server to prevent remote exploitation via a long mail_user parameter in GET requests.

    MERCUR WebView WebMail server enabled = false
  3. Compensating control

    Block or restrict HTTP access to the MERCUR WebView WebMail interface at the network perimeter (firewall/ACL) or deploy a WAF rule to drop requests with overly long mail_user parameters to mitigate the buffer overflow.

Event History

Mar 15, 2000
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Apr 12, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2000-0239?

CVE-2000-0239 is considered a critical vulnerability due to its potential to cause denial of service through a buffer overflow.

2

How do I fix CVE-2000-0239?

To fix CVE-2000-0239, users should upgrade to a patched version of the software that resolves this buffer overflow issue.

3

Which software versions are affected by CVE-2000-0239?

CVE-2000-0239 affects Atrium Software Mercur Mailserver 3.2 and Mercur POP3 and IMAP4 servers version 3.20.01.

4

Can CVE-2000-0239 be exploited remotely?

Yes, CVE-2000-0239 can be exploited remotely by sending specially crafted GET requests.

5

What types of attacks can be executed using CVE-2000-0239?

Exploitation of CVE-2000-0239 can lead to denial of service attacks, disrupting service availability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203