CVE-2008-1277: Input Validation
The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a denial of service (crash) via (1) SEARCH and (2) APPEND commands without required arguments, which triggers a NULL pointer dereference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1277?
CVE-2008-1277 is classified as a denial of service vulnerability that can crash the MailEnable IMAP service.
How do I fix CVE-2008-1277?
To fix CVE-2008-1277, upgrade MailEnable Professional or Enterprise Edition to version 3.14 or later.
What systems are affected by CVE-2008-1277?
CVE-2008-1277 affects MailEnable Professional and Enterprise Editions version 3.13 and earlier.
What type of attack does CVE-2008-1277 enable?
CVE-2008-1277 allows remote attackers to crash the IMAP service, causing denial of service.
How can CVE-2008-1277 be exploited?
CVE-2008-1277 can be exploited by sending SEARCH and APPEND commands without the required arguments to the IMAP service.