9

CVE-2006-6424

Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow; and (2) via crafted arguments to the STOR command to the Network Messaging Application Protocol (NMAP) daemon, resulting in a stack overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Novell ≫ Netmail Update e-ftfl Version <= 3.5.2
Novell ≫ Netmail Version 3.0.1
Novell ≫ Netmail Version 3.0.3a Update a
Novell ≫ Netmail Version 3.0.3a Update b
Novell ≫ Netmail Version 3.1
Novell ≫ Netmail Version 3.1 Update f
Novell ≫ Netmail Version 3.5
Novell ≫ Netmail Version 3.10
Novell ≫ Netmail Version 3.10 Update a
Novell ≫ Netmail Version 3.10 Update b
Novell ≫ Netmail Version 3.10 Update c
Novell ≫ Netmail Version 3.10 Update d
Novell ≫ Netmail Version 3.10 Update e
Novell ≫ Netmail Version 3.10 Update f
Novell ≫ Netmail Version 3.10 Update g
Novell ≫ Netmail Version 3.10 Update h
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 59.47% 0.99
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://secure-support.novell.com/KanisaPlatform/Publishing/134/3096026_f.SAL_Public.html
Patch
http://secunia.com/advisories/23437
Patch
Vendor Advisory
http://securityreason.com/securityalert/2081
http://securitytracker.com/id?1017437
Patch
http://www.cirt.dk/advisories/cirt-48-advisory.txt
Patch
Vendor Advisory
http://www.kb.cert.org/vuls/id/381161
US Government Resource
http://www.kb.cert.org/vuls/id/912505
US Government Resource
http://www.securityfocus.com/archive/1/455201/100/0/threaded
http://www.securityfocus.com/archive/1/455202/100/0/threaded
http://www.securityfocus.com/bid/21724
http://www.securityfocus.com/bid/21725
http://www.vupen.com/english/advisories/2006/5134
http://www.zerodayinitiative.com/advisories/ZDI-06-052.html
Patch
Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-06-053.html
Patch
Vendor Advisory