CVE-2006-6425
Novell NetMail IMAP APPEND Buffer Overflow Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via unspecified vectors involving the APPEND command.
Desbordamiento de búfer basado en pila en el demonio IMAP (IMAPD) de Novell NetMail anterior a 3.52e FTF2 permite a atacantes remotos autenticados ejecutar código de su elección mediante vectores no especificados que implican el parámetro APPEND.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Novell NetMail. Successful exploitation requires the attacker to successfully authenticate to the affected service.
The specific flaw exists in the NetMail IMAP server's handling of the APPEND command. A lack of bounds checking on a specific parameter to this command can lead to a stack-based buffer overflow. This vulnerability can be exploited to execute arbitrary code.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-12-09 CVE Reserved
- 2006-12-22 CVE Published
- 2010-05-09 First Exploit
- 2024-08-07 CVE Updated
- 2024-09-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/2080 | Third Party Advisory | |
http://www.kb.cert.org/vuls/id/258753 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/455200/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/21723 | Vdb Entry | |
http://www.vupen.com/english/advisories/2006/5134 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/16488 | 2010-05-09 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/23437 | 2018-10-17 | |
http://securitytracker.com/id?1017437 | 2018-10-17 | |
http://www.zerodayinitiative.com/advisories/ZDI-06-054.html | 2018-10-17 | |
https://secure-support.novell.com/KanisaPlatform/Publishing/134/3096026_f.SAL_Public.html | 2018-10-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | <= 3.5.2 Search vendor "Novell" for product "Netmail" and version " <= 3.5.2" | e-ftfl |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.0.1 Search vendor "Novell" for product "Netmail" and version "3.0.1" | - |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.0.3a Search vendor "Novell" for product "Netmail" and version "3.0.3a" | a |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.0.3a Search vendor "Novell" for product "Netmail" and version "3.0.3a" | b |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.1 Search vendor "Novell" for product "Netmail" and version "3.1" | - |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.1 Search vendor "Novell" for product "Netmail" and version "3.1" | f |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.5 Search vendor "Novell" for product "Netmail" and version "3.5" | - |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.10 Search vendor "Novell" for product "Netmail" and version "3.10" | - |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.10 Search vendor "Novell" for product "Netmail" and version "3.10" | a |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.10 Search vendor "Novell" for product "Netmail" and version "3.10" | b |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.10 Search vendor "Novell" for product "Netmail" and version "3.10" | c |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.10 Search vendor "Novell" for product "Netmail" and version "3.10" | d |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.10 Search vendor "Novell" for product "Netmail" and version "3.10" | e |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.10 Search vendor "Novell" for product "Netmail" and version "3.10" | f |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.10 Search vendor "Novell" for product "Netmail" and version "3.10" | g |
Affected
| ||||||
Novell Search vendor "Novell" | Netmail Search vendor "Novell" for product "Netmail" | 3.10 Search vendor "Novell" for product "Netmail" and version "3.10" | h |
Affected
|