CVE-2006-5177: Buffer Overflow
The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecified vectors involving crafted base64 encoded NTLM Type 3 messages, or (2) cause a denial of service via crafted base64 encoded NTLM Type 1 messages, which trigger a buffer over-read.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5177?
CVE-2006-5177 is considered to have a high severity due to its potential to allow remote code execution and denial of service.
How do I fix CVE-2006-5177?
To fix CVE-2006-5177, upgrade to the latest version of MailEnable that addresses this vulnerability.
What versions of MailEnable are affected by CVE-2006-5177?
CVE-2006-5177 affects MailEnable Professional and Enterprise version 2.0.
Can CVE-2006-5177 lead to data theft?
Yes, CVE-2006-5177 has the potential to lead to data theft through remote code execution.
What type of attacks can be executed using CVE-2006-5177?
CVE-2006-5177 can be exploited to execute arbitrary code or cause denial of service using crafted NTLM messages.