31442Third-party advisory
http://secunia.com/advisories/31442 CVE-2008-3606
Qbik WinGate 6.2.2 - 'LIST' Remote Denial of Service
Record summary
CVE-2008-3606 has a selected CVSS score of 6.5; EIP currently links 1 catalogued exploit.
Description
Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (resource exhaustion) or possibly execute arbitrary code via a long argument to the LIST command. NOTE: some of these details are obtained from third party information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQbik WinGate 6.2.2 - 'LIST' Remote Denial of ServiceExploitDB exploitby AntunesNot analyzed1 file
References
74146Third-party advisory
http://securityreason.com/securityalert/4146 20080808 [AJECT] WinGate Email Server (IMAP) vulnerabilitymailing list
http://www.securityfocus.com/archive/1/495264/100/0/threaded 30606vdb entry
http://www.securityfocus.com/bid/30606 1020644vdb entry
http://www.securitytracker.com/id?1020644 wingate-imapserver-bo(44370)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/44370 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-3606