Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2002-1076

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2002-1076
Last Modified 05 Sep 2008 04:29:42
Published 04 Oct 2002 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2002-1076

Summary

Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.

Vulnerable Systems

Application

  • Ipswitch Imail 6.1

  • Ipswitch Imail 6.2

  • Ipswitch Imail 6.3

  • Ipswitch Imail 6.4

  • Ipswitch Imail 7.0.1

  • Ipswitch Imail 7.0.2

  • Ipswitch Imail 7.0.3

  • Ipswitch Imail 7.0.4

  • Ipswitch Imail 7.0.5

  • Ipswitch Imail 7.0.6

  • Ipswitch Imail 7.0.7

  • Ipswitch Imail 7.1


References

BID - 5323

XF - imail-web-messaging-bo(9679)

CONFIRM - http://support.ipswitch.com/kb/IM-20020731-DM02.htm

CONFIRM - http://support.ipswitch.com/kb/IM-20020729-DM01.htm

BUGTRAQ - 20020729 Re: Hoax Exploit (2c79cbe14ac7d0b8472d3f129fa1df55 RETURNS)

BUGTRAQ - 20020729 Hoax Exploit

BUGTRAQ - 20020725 IPSwitch IMail ADVISORY/EXPLOIT/PATCH


Last Updated: 27 May 2016 10:37:11