CVE-2005-4559: Medium severity Deerfield Visnetic Mail Server vulnerability
mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the defaultlayout and layoutsettings variables when an unrecognized HTTPUSERAGENT string is provided, which allows remote attackers to access arbitrary files via a request with an unrecognized User Agent that also specifies the desired defaultlayout and layoutsettings parameters.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4559?
CVE-2005-4559 is classified as a medium severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2005-4559?
To fix CVE-2005-4559, you should update to the latest version of the affected software which addresses this vulnerability.
Which versions are affected by CVE-2005-4559?
CVE-2005-4559 affects IceWarp Web Mail version 5.5.1, Merak Mail Server version 8.3.0r, and VisNetic Mail Server version 8.3.0 build 1.
What impact can CVE-2005-4559 have on affected systems?
CVE-2005-4559 may allow remote attackers to manipulate the layout settings, leading to potential unauthorized access or disruption of service.
Is there a workaround for CVE-2005-4559?
A workaround for CVE-2005-4559 includes configuring the servers to restrict access based on user agent strings until a patch can be applied.