Multiple buffer overflows in MailEnable Professional 1.71 and Enterprise 1.1 before patch ME-10009 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) LIST, (2) LSUB, and (3) UID FETCH commands. NOTE: it is possible that these are alternate vectors for the issue described in CVE-2005-4402.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mailenable_enterprise | Mailenable | 1.1 (including) | 1.1 (including) |
Mailenable_professional | Mailenable | 1.71 (including) | 1.71 (including) |