IA Webmail contains a flaw that allows a remote attacker to execute arbitrary code. The issue is due to a boundary error in the web service when handling HTTP GET requests. This can be exploited to cause a buffer overflow by sending an overly long, specially crafted GET request to a vulnerable system, resulting in the attacker being able to execute code remotely.
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workarounds:
1) Filter long requests in a HTTP proxy or firewall with URL filtering capabilities.
2) Restrict access to the web service (default port 8180/tcp) allowing only trusted IPs to connect
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.