CVE-2009-3838: Buffer Overflow
Published Nov 2, 2009
·Updated
Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long error message.
Affected Software
2 affected components
Pmail Pegasus Mail=4.51
Pmail Pegasus Mail=4.41
Event History
Nov 2, 2009
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3838?
CVE-2009-3838 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2009-3838?
To mitigate CVE-2009-3838, upgrade Pegasus Mail to version 4.51 or later, which addresses the vulnerability.
3
Which versions of Pegasus Mail are affected by CVE-2009-3838?
CVE-2009-3838 affects Pegasus Mail versions 4.41 and 4.51.
4
What type of attack does CVE-2009-3838 enable?
CVE-2009-3838 enables attackers to execute arbitrary code or cause a denial of service due to a stack-based buffer overflow.
5
Is CVE-2009-3838 a local or remote vulnerability?
CVE-2009-3838 is a remote vulnerability that can be exploited through a POP3 server.