CVE-2007-4440: Buffer Overflow
Published Aug 21, 2007
·Updated
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961.
Affected Software
1 affected component
Pmail Mercury Mail Transport System<=4.51
Event History
Aug 21, 2007
CVE Published
12:17 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4440?
CVE-2007-4440 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2007-4440?
To fix CVE-2007-4440, update the Mercury Mail Transport System to a version later than 4.51.
3
What type of vulnerability is CVE-2007-4440?
CVE-2007-4440 is a stack-based buffer overflow vulnerability.
4
Can CVE-2007-4440 be exploited remotely?
Yes, CVE-2007-4440 can be exploited remotely by attackers sending a long AUTH CRAM-MD5 string.
5
What software is affected by CVE-2007-4440?
CVE-2007-4440 affects the Mercury Mail Transport System versions up to and including 4.51.