CVE-2008-7182: Buffer Overflow
Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long first argument to the APPEND command, a different vector than CVE-2008-1497 and CVE-2008-1498. NOTE: due to lack of details, it is not certain whether this is the same issue as CVE-2008-2859.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7182?
CVE-2008-7182 has a high severity due to the potential for denial of service and arbitrary code execution.
How do I fix CVE-2008-7182?
To mitigate CVE-2008-7182, upgrade from NetWin Surgemail version 3.9e to version 3.9g2 or later.
Who can exploit CVE-2008-7182?
CVE-2008-7182 can be exploited by remote authenticated users who can send specially crafted commands.
What impact does CVE-2008-7182 have on systems?
CVE-2008-7182 can lead to system crashes and may allow attackers to execute arbitrary code.
Which versions of Surgemail are affected by CVE-2008-7182?
CVE-2008-7182 affects NetWin Surgemail version 3.9e and possibly other versions prior to 3.9g2.