CVE
- Id
- 5799
- CVE No.
- CVE-2002-1415
- Status
- Candidate
- Description
- Format string vulnerability in SMTP service for WebEasyMail 3.4.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in SMTP requests.
- Phase
- Proposed (20030317)
- Votes
- ACCEPT(1) Cole | NOOP(2) Cox, Wall | REVIEWING(1) Baker
- Comments
- Baker> There is an updated version available from the vendor"s website, | http://www.51webmail.com/downloadwem.html | however, I am unable to determine whether this bug has been fixed or | not, since the site is in Chinese. There is no english language version | of it, apparently. There is an upgrade notes and patch listing under the | download menu, so if we have someone with chinese language skills, we might | be able to get this one sorted out...