CVE-2008-7182: Buffer Overflow

Published Sep 8, 2009
·
Updated

Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long first argument to the APPEND command, a different vector than CVE-2008-1497 and CVE-2008-1498. NOTE: due to lack of details, it is not certain whether this is the same issue as CVE-2008-2859.

Affected Software

1 affected component
Netwin Surgemail=3.9e

Event History

Sep 8, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2008-7182?

CVE-2008-7182 has a high severity due to the potential for denial of service and arbitrary code execution.

2

How do I fix CVE-2008-7182?

To mitigate CVE-2008-7182, upgrade from NetWin Surgemail version 3.9e to version 3.9g2 or later.

3

Who can exploit CVE-2008-7182?

CVE-2008-7182 can be exploited by remote authenticated users who can send specially crafted commands.

4

What impact does CVE-2008-7182 have on systems?

CVE-2008-7182 can lead to system crashes and may allow attackers to execute arbitrary code.

5

Which versions of Surgemail are affected by CVE-2008-7182?

CVE-2008-7182 affects NetWin Surgemail version 3.9e and possibly other versions prior to 3.9g2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203