CVE-2002-1077: Medium severity Ipswitch IMail vulnerability
Published Aug 31, 2002
·Updated
IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field.
Affected Software
12 affected components
Ipswitch IMail=6.4
Ipswitch IMail=7.0.5
Ipswitch IMail=7.0.2
Ipswitch IMail=7.0.1
Ipswitch IMail=7.1
Ipswitch IMail=7.0.7
Ipswitch IMail=7.0.6
Ipswitch IMail=6.1
Ipswitch IMail=6.3
Ipswitch IMail=7.0.4
Ipswitch IMail=6.2
Ipswitch IMail=7.0.3
Event History
Aug 31, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1077?
CVE-2002-1077 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2002-1077?
To mitigate CVE-2002-1077, ensure that your IPSwitch IMail software is updated to a patched version.
3
Which versions of IPSwitch IMail are affected by CVE-2002-1077?
CVE-2002-1077 affects IPSwitch IMail versions 6.1, 6.2, 6.3, 6.4, and 7.0.1 through 7.1 along with 7.0.2 to 7.0.7.
4
What kind of attack does CVE-2002-1077 allow?
CVE-2002-1077 allows remote attackers to cause the application to crash by sending a specific HTTP POST request.
5
Is CVE-2002-1077 still a risk for current systems?
CVE-2002-1077 is a legacy vulnerability and is primarily a risk for systems still running unsupported versions of IPSwitch IMail.