Family: Denial of Service --> Category: denial
MailEnable HTTPMail Service Authorization Buffer Overflow Vulnerability Vulnerability Scan
Vulnerability Scan Summary
Checks for Authorization Buffer Overflow Vulnerability in MailEnable HTTPMail Service
Detailed Explanation for this Vulnerability Test
The target is running at least one instance of MailEnable -
http://www.mailenable.com/ - that has a flaw in the HTTPMail service
(MEHTTPS.exe) in the Professional and Enterprise Editions. The flaw
can be exploited by issuing an HTTP request with a malformed
Authorization header, which causes a buffer overflow in HTTPMail
Successful exploitation will result in code execution on the remote
Solution : Apply hotfix : HTTPMail Fix - For MailEnable Professional
and Enterprise (65k) - 22nd April 2005.
See also : http://www.mailenable.com/hotfix/
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.