CVE-2007-5466 (CNNVD-200710-292)
中文标题:
eXtremail多个远程溢出漏洞
英文标题:
Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unkno...
漏洞描述
中文描述:
eXtremail是一个pop3/smtpd邮件服务软件,可以运行在Linux和AIX系统下。 eXtremail在验证memmove()的长度参数时存在整数下溢漏洞,管理接口和PLAIN认证中存在栈溢出漏洞,CRAM-MD5认证和recv()循环中存在堆溢出漏洞。如果远程攻击者向邮件服务台发布的畸形请求的话,就可以触发这些溢出,导致拒绝服务或执行任意代码。
英文描述:
Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code via a long string in an IMAP AUTHENTICATE PLAIN action, involving the ifParseAuthPlain function; (3) execute arbitrary code via a long LOGIN command to the admin interface port (4501/tcp); or (4) execute arbitrary code via a long string in an IMAP AUTHENTICATE LOGIN (aka CRAM-MD5 authentication) action, involving the ifProcImapAuth1 function.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| extremail | extremail | * | - | - |
cpe:2.3:a:extremail:extremail:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
exploitdb
cve.org
cve.org
exploitdb
exploitdb
CVSS评分详情
AV:N/AC:L/Au:N/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2007-5466 |
2025-11-11 15:17:56 | 2025-11-11 07:32:47 |
| NVD | nvd_CVE-2007-5466 |
2025-11-11 14:52:12 | 2025-11-11 07:41:33 |
| CNNVD | cnnvd_CNNVD-200710-292 |
2025-11-11 15:08:58 | 2025-11-11 07:49:21 |
| EXPLOITDB | exploitdb_EDB-4533 |
2025-11-11 15:05:26 | 2025-11-11 08:48:25 |
| EXPLOITDB | exploitdb_EDB-4534 |
2025-11-11 15:05:26 | 2025-11-11 08:48:26 |
| EXPLOITDB | exploitdb_EDB-4535 |
2025-11-11 15:05:24 | 2025-11-11 08:48:27 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 15 -> 16
- tags_count: 8 -> 9
查看详细变更
- references_count: 14 -> 15
查看详细变更
- references_count: 11 -> 14
- tags_count: 0 -> 8
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200710-292
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 10.0
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']