CVE-2002-1076: Buffer Overflow
Published Oct 4, 2002
·Updated
Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.
Affected Software
12 affected components
Ipswitch IMail=6.1
Ipswitch IMail=6.2
Ipswitch IMail=6.3
Ipswitch IMail=6.4
Ipswitch IMail=7.0.1
Ipswitch IMail=7.0.2
Ipswitch IMail=7.0.3
Ipswitch IMail=7.0.4
Ipswitch IMail=7.0.5
Ipswitch IMail=7.0.6
Ipswitch IMail=7.0.7
Ipswitch IMail=7.1
Remediation
Patch Available
Patch Available
Event History
Oct 4, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What vulnerabilities are associated with CVE-2002-1076?
CVE-2002-1076 is associated with a buffer overflow in the Web Messaging daemon for Ipswitch IMail that allows remote code execution.
2
How severe is CVE-2002-1076?
CVE-2002-1076 has been assigned a high severity level due to its potential to allow remote attackers to execute arbitrary code.
3
Which versions of Ipswitch IMail are affected by CVE-2002-1076?
Versions of Ipswitch IMail prior to 7.12, including 6.1 through 7.1, are affected by CVE-2002-1076.
4
How can I fix the vulnerability CVE-2002-1076?
To fix CVE-2002-1076, upgrade your Ipswitch IMail server to version 7.12 or later.
5
What type of attacks can exploit CVE-2002-1076?
CVE-2002-1076 can be exploited through long HTTP GET requests targeting the Web Messaging daemon.