CVE-2004-2401: Buffer Overflow
Published Dec 31, 2004
·Updated
Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text."
Affected Software
1 affected component
Ipswitch IMail Express=8.03
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Aug 17, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2401?
CVE-2004-2401 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2004-2401?
To fix CVE-2004-2401, upgrade to Ipswitch IMail Express version 8.05 or later.
3
What types of attacks are possible with CVE-2004-2401?
CVE-2004-2401 allows remote attackers to execute arbitrary code through specially crafted HTML messages.
4
Which versions of Ipswitch IMail Express are affected by CVE-2004-2401?
Ipswitch IMail Express versions prior to 8.05, including 8.03, are affected by CVE-2004-2401.
5
Is CVE-2004-2401 related to web messaging functionality?
Yes, CVE-2004-2401 specifically affects the Web Messaging component of Ipswitch IMail Express.