>> Surgemail "LIST" and "LSUB" Commands Buffer Overflow Vulnerability
Title : Surgemail "LIST" and "LSUB" Commands Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-0901 CVE ID : CVE-2008-1497 - CVE-2008-1498
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-17
Technical Description
A vulnerability has been identified in NetWin Surgemail, which could be exploited by attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the IMAP server when handling overly long arguments passed to the "LIST" or "LSUB" command, which could be exploited by authenticated attackers to crash an affected server or execute arbitrary code with elevated privileges.