CVE

Id
5799  
CVE No.
CVE-2002-1415  
Status
Candidate  
Description
Format string vulnerability in SMTP service for WebEasyMail 3.4.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in SMTP requests.  
Phase
Proposed (20030317)  
Votes
ACCEPT(1) Cole | NOOP(2) Cox, Wall | REVIEWING(1) Baker  
Comments
Baker> There is an updated version available from the vendor"s website, | http://www.51webmail.com/downloadwem.html | however, I am unable to determine whether this bug has been fixed or | not, since the site is in Chinese. There is no english language version | of it, apparently. There is an upgrade notes and patch listing under the | download menu, so if we have someone with chinese language skills, we might | be able to get this one sorted out...