CVE-2011-3579: Medium severity IceWarp Mail Server vulnerability
server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3579?
CVE-2011-3579 has been categorized with a medium severity level due to its potential to allow remote file access and denial of service.
How do I fix CVE-2011-3579?
To mitigate CVE-2011-3579, upgrade to IceWarp Mail Server version 10.3.3 or later.
Which versions of IceWarp Mail Server are affected by CVE-2011-3579?
CVE-2011-3579 affects IceWarp Mail Server versions 9.3.0 through 10.3.2.
Can CVE-2011-3579 lead to intranet attacks?
Yes, CVE-2011-3579 may enable attackers to send HTTP requests to intranet servers.
What is the risk of denial of service related to CVE-2011-3579?
Exploitation of CVE-2011-3579 can lead to denial of service via excessive CPU and memory consumption.