CVE-2006-4364: Buffer Overflow
Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via long strings that contain '@' characters in the (1) USER and (2) APOP commands.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4364?
CVE-2006-4364 has been classified with a high severity due to its potential to cause denial of service and execute arbitrary code.
How do I fix CVE-2006-4364?
To fix CVE-2006-4364, upgrade your Alt-N Technologies MDaemon to version 9.0.6 or later.
What type of attacks can CVE-2006-4364 facilitate?
CVE-2006-4364 can facilitate denial of service attacks and possibly allow remote code execution.
Which versions of MDaemon are affected by CVE-2006-4364?
MDaemon versions prior to 9.0.6, including 6.8.3, 3.5.4, and several others, are affected by CVE-2006-4364.
What commands are exploited in CVE-2006-4364?
CVE-2006-4364 exploits the USER and APOP commands to trigger the buffer overflow vulnerability.