The webmail interface for Ipswitch IMail 7.04 and earlier allows remote authenticated users to cause a denial of service (crash) via a mailbox name that contains a large number of . (dot) or other characters to programs such as (1) readmail.cgi or (2) printmail.cgi, possibly due to a buffer overflow that may allow execution of arbitrary code.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Imail | Ipswitch | 6.0.2 (including) | 6.0.2 (including) |
Imail | Ipswitch | 6.0.6 (including) | 6.0.6 (including) |
Imail | Ipswitch | 7.0.4 (including) | 7.0.4 (including) |