First published: Sat Jul 21 2007(Updated: )
Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ipswitch IMail Secure Server | <=2006.2 | |
Ipswitch Ipswitch Collaboration Suite | <=2006.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3925 is classified as a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2007-3925, upgrade to Ipswitch IMail Server version 2006.21 or later.
CVE-2007-3925 affects users of Ipswitch IMail Server 2006 prior to version 2006.21.
CVE-2007-3925 can be exploited through the Search and Search Charset commands in the IMAP service.
No, CVE-2007-3925 requires that the attacker is an authenticated user in order to exploit the vulnerability.