This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MailEnable Multiple Vulns - update available

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://secunia.com/advisories/22179/
Release Date: 2006-10-02
Critical: Highly critical
Impact: DoS, System access
Where: From remote
Solution Status: Vendor Patch
Software: MailEnable Enterprise Edition 2.x, MailEnable Professional 2.x
…The vulnerabilities have been reported in MailEnable Professional 2.0 and MailEnable Enterprise 2.0. Other versions may also be affected.
Solution: Apply hotfix:
- http://www.mailenable.com/hotfix/
ME-10015: Saturday, September 30, 2006
SMTP Service vulnerability fix
Priority: Critical

.
FYI…

- http://secunia.com/advisories/23105/
Release Date: 2006-11-27
Critical: Moderately critical
Impact: Security Bypass
Where: From remote
Solution Status: Vendor Patch
…The vulnerability is reported in the following versions:
* Professional Edition 2.32
* Enterprise Edition 2.32
Solution: Apply hotfix:
> http://www.mailenable.com/hotfix/
ME-10017: Monday, November 27, 2006
NetWebAdmin Critical Update
Priority: Critical
Applies to:
Professional Edition 2.32
Enterprise Edition 2.32

.
FYI…

- http://secunia.com/advisories/23080/
Release Date: 2006-11-30
Critical: Moderately critical
Impact: DoS, System access
Where: From remote
Solution Status: Partial Fix
Software: MailEnable Enterprise Edition 1.x, 2.x, MailEnable Professional 1.x, 2.x
Description: …An input validation error…can be exploited to cause a stack overflow and crash the service…
Solution: Apply hotfix…

- http://www.mailenable.com/hotfix/
ME-10020: Thursday, November 30, 2006
IMAP Critical Hotfix/Update
Priority: Critical
Applies to:
1.6-1.83 Professional Edition
1.1-1.40 Enterprise Edition
2.0-2.33 Professional Edition
2.0-2.33 Enterprise Edition
Reason: Denial of Service and Potential Buffer Overflow Vulnerability within IMAP module

.
FYI…

MailEnable IMAP Service Buffer Overflow Vuln
- http://secunia.com/advisories/23201/
Release Date: 2006-12-08
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch…
…vulnerability is caused due to a NULL pointer dereference error when handling data sent to the IMAP service. This can be exploited to crash the system via a specially crafted sequence of commands and data…
Solution:
Apply hotfix ME-10025…
http://www.mailenable.com/hotfix/
ME-10025: Friday, December 08, 2006
IMAP Critical Hotfix/Update
Priority: Critical
Applies to:
1.6-1.84 Professional Edition
1.1-1.41 Enterprise Edition
2.0-2.35 Professional Edition
2.0-2.35 Enterprise Edition
Reason:
+ Denial of Service and Potential Buffer Overflow Vulnerability within IMAP module
+ Mailbox quotas may not be correctly recalculated when the quota is exceeded or a mailbox delivery timeout occurs.
+ Custom/Third Party mailbox delivery events may not fire…"

MailEnable IMAP Service Denial Of Service Vuln
- http://secunia.com/advisories/23267/
Release Date: 2006-12-08
Critical: Moderately critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch…
…vulnerability is caused due to a boundary error in the IMAP service and can be exploited to cause a stack-based buffer overflow via a specially crafted sequence of commands and data.
Solution: Apply hotfix ME-10023…
- http://www.mailenable.com/hotfix/
ME-10023: Saturday, December 02, 2006
IMAP Critical Hotfix/Update
Priority: Critical
Applies to:
1.6-1.83 Professional Edition
1.1-1.40 Enterprise Edition
2.0-2.34 Professional Edition
2.0-2.34 Enterprise Edition
FYI…

- http://secunia.com/advisories/23127/
Release Date: 2006-12-18
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
…The vulnerability is confirmed in MailEnable Enterprise Edition 2.35 and MailEnable Professional Edition 2.35. Other versions may also be affected.
Solution: Apply hotfix:
http://www.mailenable.com/hotfix/ …
ME-10027: Monday, December 18, 2006
MailEnable Core Services Security Update
Priority: Critical …
Reason:
+ This security update provides updated services for MailEnable Standard, Professional, and Enterprise Editions.
+ The services have been updated to include additional checking/prevention against exploitation through any unforseen buffer overflow vulnerabilities.
+ These updates also contain patches to all previously published MailEnable hotfixes.

ME-10026: Monday, December 18, 2006
POP
Priority: Critical …
Reason:
+ Security Vulnerability with MailEnable POP Service …

:ph34r:
FYI…

- http://secunia.com/advisories/23998/
Release Date: 2007-02-14
Critical: Moderately critical
Impact: Cross Site Scripting
Where: From remote
Solution Status: Vendor Patch
Software: MailEnable Enterprise Edition 1.x, Enterprise Edition 2.x, Professional 1.x, Professional 2.x
…The vulnerabilities are confirmed in version MailEnable Professional 2.351. Other versions may also be affected.
Solution:
MailEnable Enterprise 2.x: Update to version 2.37.
MailEnable Professional 2.x: Update to version 2.37.
MailEnable Enterprise 1.x: Update to version 1.42.
MailEnable Professional 1.x: Update to version 1.85.

> http://www.mailenable.com/download.asp

- http://secunia.com/advisories/24139/
Release Date: 2007-02-14
Critical: Moderately critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch
Software: MailEnable Enterprise Edition 2.x, MailEnable Professional 2.x
…The vulnerability is confirmed in MailEnable Professional version 2.35. Other versions may also be affected.
Solution: Update to version 2.351 or later…"

:ph34r:
Updated:

- http://www.mailenable.com/hotfix/
> ME-10030: Friday, March 16, 2007
SMTP Service hotfix
Priority: Moderate
Patch for Professional and Enterprise versions 2.3X - 2.37 (inclusive).
Reason:
+This patch updates the MailEnable SMTP Connector to address a bug where some NDRs could be placed in the wrong queue location.
+The patch also includes an update to the MailEnable MTA to prevent message duplication should file contention occur.
1. Download this file
2. Instructions are contained within the associated Read-Me.txt

> ME-10029: Tuesday, March 06, 2007
IMAP Critical Hotfix/Update
Priority: Critical
Applies to:
1.6-1.85 Professional Edition
1.1-1.42 Enterprise Edition
2.0-2.37 Professional Edition
2.0-2.37 Enterprise Edition …"

.
FYI…

- http://www.mailenable.com/hotfix/
ME-10031: Tuesday, April 03, 2007
MailEnable Security Lockdown Utility
Priority: Recommendation
Applies to: MailEnable 1.X and 2.X Versions
Reason: This update significantly locks down the rights and permissions required for MailEnable protocol services.
More information on the update is available here: http://www.mailenable.com/security/lockdown.asp
1. Download the ME-10031.EXE file associated with this update notice
2. Run the executable
3. Additional information on the update are outlined in the associated Read-Me.txt (also located in Mail Enable\Updates\ME-10031)
Note: Plesk users should review KB Article ME020478* before applying this update.
Also, if you are running the update on a domain controller, you should check that the IME_SYSTEM account is assigned the "Logon as Service" right under the Administraive Tools|Local Security Policy"
http://www.mailenable.com/hotfix/ME-10031.EXE

> http://www.mailenable.com/hotfix/ME-10031-Read-Me.txt

* http://www.mailenable.com/?ID=ME020478

.