CVE-2001-1283: Buffer Overflow
The webmail interface for Ipswitch IMail 7.04 and earlier allows remote authenticated users to cause a denial of service (crash) via a mailbox name that contains a large number of . (dot) or other characters to programs such as (1) readmail.cgi or (2) printmail.cgi, possibly due to a buffer overflow that may allow execution of arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1283?
CVE-2001-1283 is classified as a moderate severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2001-1283?
To fix CVE-2001-1283, upgrade to a version of Ipswitch IMail that is later than 7.0.4, as earlier versions are affected.
Who is affected by CVE-2001-1283?
CVE-2001-1283 affects users of Ipswitch IMail versions 6.0.2, 6.0.6, and 7.0.4.
What type of attack is facilitated by CVE-2001-1283?
CVE-2001-1283 facilitates a denial of service attack through the exploitation of mailbox names with excessive characters.
Is CVE-2001-1283 exploitable remotely?
Yes, CVE-2001-1283 can be exploited remotely by authenticated users.