CVE-2008-1498: Buffer Overflow
Published Mar 25, 2008
·Updated
Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code via a long first argument to the LIST command.
Affected Software
1 affected component
Netwin Surgemail<=3.8k4
Event History
Mar 25, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1498?
CVE-2008-1498 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2008-1498?
To fix CVE-2008-1498, upgrade to a version of NetWin SurgeMail later than 3.8k4.
3
Who is affected by CVE-2008-1498?
Remote authenticated users of NetWin SurgeMail version 3.8k4 and earlier are affected by CVE-2008-1498.
4
What kind of vulnerability is CVE-2008-1498?
CVE-2008-1498 is a stack-based buffer overflow vulnerability in the IMAP service of SurgeMail.
5
What can an attacker do with CVE-2008-1498?
An attacker can execute arbitrary code on the server by exploiting the buffer overflow in the LIST command.