First published: Tue Mar 25 2008(Updated: )
Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code via long arguments to the LSUB command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetWin SurgeMail | =3.6f7 | |
NetWin SurgeMail | =3.0c2 | |
NetWin SurgeMail | =2.2a6 | |
NetWin SurgeMail | =3.7b | |
NetWin SurgeMail | =3.8d | |
NetWin SurgeMail | =2.0g2 | |
NetWin SurgeMail | =3.8b | |
NetWin SurgeMail | =3.7b8 | |
NetWin SurgeMail | =3.8i3 | |
NetWin SurgeMail | =2.0e | |
NetWin SurgeMail | =3.8a | |
NetWin SurgeMail | =3.5b3 | |
NetWin SurgeMail | =3.8k3 | |
NetWin SurgeMail | =3.7b6 | |
NetWin SurgeMail | =2.0c | |
NetWin SurgeMail | =2.2g2 | |
NetWin SurgeMail | =3.8f2 | |
NetWin SurgeMail | =3.8m | |
NetWin SurgeMail | =3.7b3 | |
NetWin SurgeMail | =3.8f | |
NetWin SurgeMail | =3.2e | |
NetWin SurgeMail | =2.2c10 | |
NetWin SurgeMail | =3.6d | |
NetWin SurgeMail | =2.2g3 | |
NetWin SurgeMail | =3.7b7 | |
NetWin SurgeMail | =1.8g3 | |
NetWin SurgeMail | =3.8i2 | |
NetWin SurgeMail | =3.6f5 | |
NetWin SurgeMail | =2.0a2 | |
NetWin SurgeMail | =3.8i | |
NetWin SurgeMail | =3.7b5 | |
NetWin SurgeMail | =3.8k | |
NetWin SurgeMail | =2.1c7 | |
NetWin SurgeMail | =3.8f3 | |
NetWin SurgeMail | =3.8k2 | |
NetWin SurgeMail | =3.5a | |
NetWin SurgeMail | =1.9b2 | |
NetWin SurgeMail | =3.0a | |
NetWin SurgeMail | =3.6f3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1497 is a critical vulnerability due to a stack-based buffer overflow that can allow remote authenticated users to execute arbitrary code.
To fix CVE-2008-1497, upgrade to a version of NetWin SurgeMail that is not affected by this vulnerability.
Versions of SurgeMail from 38k4-4 and earlier are affected by CVE-2008-1497.
Yes, CVE-2008-1497 can be exploited remotely by authenticated users through long arguments to the LSUB command.
Systems running affected versions of NetWin SurgeMail, especially those allowing remote authenticated access, are at risk from CVE-2008-1497.