CVE-2005-4456: Buffer Overflow
Multiple buffer overflows in MailEnable Professional 1.71 and Enterprise 1.1 before patch ME-10009 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) LIST, (2) LSUB, and (3) UID FETCH commands. NOTE: it is possible that these are alternate vectors for the issue described in CVE-2005-4402.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4456?
CVE-2005-4456 is considered a critical vulnerability due to its potential to allow remote code execution and denial of service.
How do I fix CVE-2005-4456?
To fix CVE-2005-4456, upgrade to MailEnable Professional version 1.72 or Enterprise version 1.2 or apply the patch ME-10009.
What versions of MailEnable are affected by CVE-2005-4456?
CVE-2005-4456 affects MailEnable Professional version 1.71 and Enterprise version 1.1.
What types of commands can exploit CVE-2005-4456?
The vulnerability in CVE-2005-4456 can be exploited through long LIST, LSUB, and UID FETCH commands.
What is the impact of CVE-2005-4456 on MailEnable services?
CVE-2005-4456 can lead to service crashes and the potential execution of arbitrary code.