CVE-2004-2422: Medium severity Ipswitch IMail vulnerability
Multiple features in Ipswitch IMail Server before 8.13 allow remote attackers to cause a denial of service (crash) via (1) a long sender field to the Queue Manager or (2) a long To field to the Web Messaging component.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2422?
CVE-2004-2422 is classified as a denial of service vulnerability that can crash the Ipswitch IMail Server.
How do I fix CVE-2004-2422?
To fix CVE-2004-2422, upgrade to a patched version of Ipswitch IMail Server that addresses this vulnerability.
What versions of Ipswitch IMail are affected by CVE-2004-2422?
CVE-2004-2422 affects multiple versions including 5.0, 6.0.4, 8.1, and several others leading up to version 8.13.
Can CVE-2004-2422 be exploited remotely?
Yes, CVE-2004-2422 can be exploited by remote attackers via specially crafted long sender or To fields.
What components of Ipswitch IMail are vulnerable in CVE-2004-2422?
The vulnerability in CVE-2004-2422 affects the Queue Manager and the Web Messaging component of Ipswitch IMail.