A remote overflow exists in MailEnable Professional and Enterprise. The product fails to validate input to the IMAP STATUS command resulting in a stack-based buffer overflow. With a specially crafted request, an authenticated attacker can cause the service to fail, and may be able to execute arbitrary code with System privileges, resulting in a loss of integrity.
Upgrade to MailEnable Professional version 1.6, MailEnable Enterprise version 1.1 or higher, as it has been reported to fix this vulnerability. In addition, MailEnable has released a patch for some older versions.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.