CVE-2006-6424: Buffer Overflow
Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow; and (2) via crafted arguments to the STOR command to the Network Messaging Application Protocol (NMAP) daemon, resulting in a stack overflow.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6424?
CVE-2006-6424 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2006-6424?
To fix CVE-2006-6424, upgrade Novell NetMail to version 3.52e FTF2 or later.
What types of buffer overflow are involved in CVE-2006-6424?
CVE-2006-6424 involves heap overflow vulnerabilities caused by command continuation requests and crafted arguments.
Which versions of Novell NetMail are affected by CVE-2006-6424?
CVE-2006-6424 affects various versions of Novell NetMail, including 3.1 up to 3.5.2.
Can CVE-2006-6424 be exploited remotely?
Yes, CVE-2006-6424 can be exploited remotely by attackers to execute arbitrary code.