CVE-2006-6291

Stack overflow in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.83 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.40 and 2.0 through 2.33, allows remote authenticated users to cause a denial of service (crash) via a long argument containing * (asterisk) and ? (question mark) characters to the DELETE command, as addressed by the ME-10020 hotfix.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:mailenable:mailenable:*:*:*:*:professional:*:*:*
cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:mailenable:mailenable:*:*:*:*:professional:*:*:*

History

21 Nov 2024, 00:22

Type Values Removed Values Added
References () http://secunia.com/advisories/23080 - Patch, Vendor Advisory () http://secunia.com/advisories/23080 - Patch, Vendor Advisory
References () http://secunia.com/secunia_research/2006-71/advisory/ - Vendor Advisory () http://secunia.com/secunia_research/2006-71/advisory/ - Vendor Advisory
References () http://securitytracker.com/id?1017276 - Third Party Advisory, VDB Entry () http://securitytracker.com/id?1017276 - Third Party Advisory, VDB Entry
References () http://securitytracker.com/id?1017319 - Third Party Advisory, VDB Entry () http://securitytracker.com/id?1017319 - Third Party Advisory, VDB Entry
References () http://www.mailenable.com/hotfix/ - Patch () http://www.mailenable.com/hotfix/ - Patch
References () http://www.securityfocus.com/archive/1/453118/100/100/threaded - Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/453118/100/100/threaded - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/21362 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/21362 - Third Party Advisory, VDB Entry
References () http://www.vupen.com/english/advisories/2006/4778 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/4778 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/30614 - VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/30614 - VDB Entry

Information

Published : 2006-12-05 11:28

Updated : 2024-11-21 00:22


NVD link : CVE-2006-6291

Mitre link : CVE-2006-6291

CVE.ORG link : CVE-2006-6291


JSON object : View

Products Affected

mailenable

  • mailenable
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer