CVE-2008-1497: Buffer Overflow
Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code via long arguments to the LSUB command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1497?
CVE-2008-1497 is a critical vulnerability due to a stack-based buffer overflow that can allow remote authenticated users to execute arbitrary code.
How do I fix CVE-2008-1497?
To fix CVE-2008-1497, upgrade to a version of NetWin SurgeMail that is not affected by this vulnerability.
What versions of SurgeMail are affected by CVE-2008-1497?
Versions of SurgeMail from 38k4-4 and earlier are affected by CVE-2008-1497.
Can CVE-2008-1497 be exploited remotely?
Yes, CVE-2008-1497 can be exploited remotely by authenticated users through long arguments to the LSUB command.
What types of systems are at risk from CVE-2008-1497?
Systems running affected versions of NetWin SurgeMail, especially those allowing remote authenticated access, are at risk from CVE-2008-1497.