CVE-2007-5466 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 19.9% (pctl 97)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code via a long string in an IMAP AUTHENTICATE PLAIN action, involving the ifParseAuthPlain function; (3) execute arbitrary code via a long LOGIN command to the admin interface port (4501/tcp); or (4) execute arbitrary code via a long string in an IMAP AUTHENTICATE LOGIN (aka CRAM-MD5 authentication) action, involving the ifProcImapAuth1 function.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 19.89% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-10-15 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| extremail | extremail |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | eXtremail 2.1.1 - 'LOGIN' Remote Stack Overflow | 2007-10-15 |
| exploit-db | eXtremail 2.1.1 - PLAIN Authentication Remote Stack Overflow | 2007-10-15 |
| exploit-db | eXtremail 2.1.1 - Remote Heap Overflow (PoC) | 2007-10-15 |
References
- http://secunia.com/advisories/27220
- http://www.digit-labs.org/files/exploits/extremail-v4.c
- http://www.digit-labs.org/files/exploits/extremail-v5.c
- http://www.digit-labs.org/files/exploits/extremail-v6.c
- http://www.digit-labs.org/files/exploits/extremail-v8.pl
- http://www.securityfocus.com/archive/1/482293
- http://www.securityfocus.com/bid/26074
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37209
- https://www.exploit-db.com/exploits/4533
- https://www.exploit-db.com/exploits/4534
- https://www.exploit-db.com/exploits/4535
- http://secunia.com/advisories/27220
- http://www.digit-labs.org/files/exploits/extremail-v4.c
- http://www.digit-labs.org/files/exploits/extremail-v5.c
- http://www.digit-labs.org/files/exploits/extremail-v6.c
- http://www.digit-labs.org/files/exploits/extremail-v8.pl
- http://www.securityfocus.com/archive/1/482293
- http://www.securityfocus.com/bid/26074
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37209
- https://www.exploit-db.com/exploits/4533
→ the Explorer · watch your stack · NVD