CVE-2007-0955: High severity MailEnable MailEnable vulnerability
The NTLMUnPackType3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to cause a denial of service (application crash) via certain base64-encoded data following an AUTHENTICATE NTLM command to the imap port (143/tcp), which results in an out-of-bounds read.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0955?
CVE-2007-0955 has a severity rating that indicates it can lead to a denial of service due to application crashes.
How do I fix CVE-2007-0955?
To fix CVE-2007-0955, upgrade MailEnable Professional to version 2.36 or later.
What types of attacks does CVE-2007-0955 enable?
CVE-2007-0955 allows remote attackers to perform denial of service attacks on vulnerable MailEnable installations.
Which versions of MailEnable are affected by CVE-2007-0955?
CVE-2007-0955 affects MailEnable Professional versions up to and including 2.35.
What component is vulnerable in CVE-2007-0955?
The vulnerable component in CVE-2007-0955 is the NTLM_UnPack_Type3 function in MENTLM.dll.