CVE-2004-2284: Critical severity Open Webmail Open WebMail vulnerability
Published Dec 31, 2004
·Updated
The readlistfromfile function in vacation.pl for OpenWebmail before 2.32 20040629 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename argument.
Affected Software
10 affected components
Open Webmail Open WebMail=1.7
Open Webmail Open WebMail=1.81
Open Webmail Open WebMail=2.30
Open Webmail Open WebMail=2.21
Open Webmail Open WebMail=1.71
Open Webmail Open WebMail=2.31
Open Webmail Open WebMail=2.20
Open Webmail Open WebMail=1.8
Open Webmail Open WebMail=1.90
Open Webmail Open WebMail=2.32
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 19, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2284?
CVE-2004-2284 has a high severity due to its potential for remote command execution.
2
How do I fix CVE-2004-2284?
To fix CVE-2004-2284, update OpenWebmail to version 2.32 or later.
3
What systems are affected by CVE-2004-2284?
CVE-2004-2284 affects OpenWebmail versions up to and including 2.31.
4
What type of attack does CVE-2004-2284 facilitate?
CVE-2004-2284 facilitates remote command execution via shell metacharacters in filename arguments.
5
Is CVE-2004-2284 still a risk in newer versions?
CVE-2004-2284 is not a risk in OpenWebmail version 2.32 and later, as these versions have patched the vulnerability.