CVE-2006-6291: Buffer Overflow
Stack overflow in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.83 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.40 and 2.0 through 2.33, allows remote authenticated users to cause a denial of service (crash) via a long argument containing (asterisk) and ? (question mark) characters to the DELETE command, as addressed by the ME-10020 hotfix.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6291?
CVE-2006-6291 is classified as a denial of service vulnerability.
How do I fix CVE-2006-6291?
To fix CVE-2006-6291, upgrade MailEnable to the latest version available.
Who is affected by CVE-2006-6291?
CVE-2006-6291 affects MailEnable Professional versions 1.6 to 1.83 and 2.0 to 2.33, and MailEnable Enterprise versions 1.1 to 1.40 and 2.0 to 2.33.
Can CVE-2006-6291 be exploited remotely?
Yes, CVE-2006-6291 can be exploited by remote authenticated users.
What causes the vulnerability in CVE-2006-6291?
The vulnerability in CVE-2006-6291 is caused by a stack overflow when processing long arguments containing asterisks and question marks.