CVE-2012-1916: High severity atmail vulnerability
Published Mar 27, 2012
·Updated
@Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to execute arbitrary code via an e-mail attachment with an executable extension, leading to the creation of an executable file under tmp/.
Affected Software
1 affected component
Atmail AtMail Open<=1.04
Remediation
Patch Available
Event History
Mar 27, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1916?
CVE-2012-1916 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2012-1916?
To fix CVE-2012-1916, update to AtMail Open-Source version 1.05 or later.
3
What versions of AtMail Open-Source are affected by CVE-2012-1916?
CVE-2012-1916 affects all versions of AtMail Open-Source prior to 1.05.
4
What could a remote attacker do using CVE-2012-1916?
A remote attacker could execute arbitrary code via a malicious email attachment, leading to unauthorized actions on the server.
5
Is there any customer data risk associated with CVE-2012-1916?
Yes, CVE-2012-1916 poses a risk to customer data as it allows attackers significant access to the affected system.