Product: MailEnable Pro
MailEnable Enterprise
http://www.mailenable.com
Version: Confirmed on MailEnable Pro 1.7 and MailEnable Enterprise 1.1
Author: Josh Zlatin-Amishav
Date: November 24, 2005
Background:
MailEnable's mail server software provides a powerful, scalable hosted
messaging platform for Microsoft Windows. MailEnable offers stability,
unsurpassed flexibility and an extensive feature set which allows you to
provide cost-effective mail services.
Issue:
In working with researchers at Tenable Network Security, I have come
across
a Denial of Service attack in the MailEnable Pro and MailEnable Enterprise
IMAP server. It is possible to remotely crash the IMAP server by sending a
To install:
1) Stop the IMAP service
2) Rename the MEIMAPS.EXE file in the Mail Enablebin directory as this
will
allow you to roll back this fix
3) Extract the zip file from the URL above to the Mail Enablebin directory
4) Start the IMAP service
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.