First published: Wed May 11 2005(Updated: )
Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the xtellmail command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetWin dMail | =3.1a | |
NetWin dMail | =3.1b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1478 has a high severity rating due to the potential for remote code execution.
To fix CVE-2005-1478, upgrade to a patched version of DMail that does not contain the format string vulnerability.
CVE-2005-1478 affects DMail versions 3.1a and 3.1b.
Yes, CVE-2005-1478 can be exploited remotely through the xtellmail command.
The impact of CVE-2005-1478 can allow attackers to execute arbitrary code on the server.