Summary
IceWarp Merak Mail Server s prone to a stack-based buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker could exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
IceWarp Merak Mail Server 9.4.1 is vulnerable
other versions may
also be affected.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2009-1516 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- IceWarp Merak Mail Server 'Base64FileEncode()' Stack-Based Buffer Overflow Vulnerability
- Generic SMTP overflows
- SpamAssassin Milter Plugin 'mlfi_envrcpt()' Remote Arbitrary Command Injection Vulnerability
- Exchange XEXCH50 Remote Buffer Overflow
- Sendmail NULL Character CA SSL Certificate Validation Security Bypass Vulnerability