CVE-2009-1516: Buffer Overflow
Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent attackers to execute arbitrary code via a large value in the second argument to the Base64FileEncode method, as possibly demonstrated by a web application that accepts untrusted input for this method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1516?
CVE-2009-1516 has a high severity rating due to its potential for enabling arbitrary code execution.
How do I fix CVE-2009-1516?
To fix CVE-2009-1516, you should update the IceWarp Merak Mail Server to the latest version that addresses this vulnerability.
What systems are affected by CVE-2009-1516?
CVE-2009-1516 specifically affects IceWarp Merak Mail Server version 9.4.1.
What is the exploit method for CVE-2009-1516?
CVE-2009-1516 can be exploited by providing a large value as the second argument to the Base64FileEncode method in the IceWarpServer.APIObject ActiveX control.
Is CVE-2009-1516 remotely exploitable?
Yes, CVE-2009-1516 can be exploited by remote attackers through crafted inputs in a web application.