Lucene search

K
saintSAINT CorporationSAINT:4A2BBA54F91189B4349E37140F42FBE5
HistoryNov 30, 2005 - 12:00 a.m.

NetMail IMAP buffer overflow

2005-11-3000:00:00
SAINT Corporation
download.saintcorporation.com
26

EPSS

0.853

Percentile

98.6%

Added: 11/30/2005
CVE: CVE-2005-3314
BID: 15491
OSVDB: 20956

Background

Novell NetMail is an e-mail and calendaring server application.

Problem

A buffer overflow in the NetMail IMAP service could allow authenticated users to execute arbitrary commands using a long, specially crafted argument to certain commands.

Resolution

Install NetMail 3.52e FTF 1.

References

<http://archives.neohapsis.com/archives/vulnwatch/2005-q4/0050.html&gt;

Limitations

Exploit works against NetMail 3.5.2.

Platforms

Windows 2000
Windows XP

EPSS

0.853

Percentile

98.6%