Vulnerability record · CVE-2004-0297 · published 23 November 2004
CVE-2004-0297: Ipswitch IMail LDAP daemon buffer overflow via large tag length
Ipswitch · Imail
The LDAP daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 has a buffer overflow triggered by an LDAP message with a large tag length. A remote, unauthenticated attacker can crash the service and potentially execute arbitrary code, making this a full-impact flaw on an internet-facing mail component.
Description
Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via an LDAP message with a large tag length.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication and complete impact, combined with a very high EPSS score and an exploit-tagged reference.
What it is
The LDAP daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 has a buffer overflow triggered by an LDAP message with a large tag length. A remote, unauthenticated attacker can crash the service and potentially execute arbitrary code, making this a full-impact flaw on an internet-facing mail component.
Impact
An attacker gains the ability to crash the LDAP daemon and, per the description, execute arbitrary code in its context, which could yield complete compromise of confidentiality, integrity and availability.
Attack surface
Reached over the network via the LDAP service; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required, only the ability to send a crafted LDAP message to the daemon.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high (0.68129, 99.3rd percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.
What to do
- Apply the vendor hotfix referenced in the Ipswitch IMail 8.05 HF2 release notes, or upgrade to a fixed IMail version.
- If patching is not immediately possible, restrict network access to the LDAP daemon (TCP 389 and any other configured LDAP ports) to trusted hosts only.
- Disable or stop the iLDAP service if LDAP functionality is not required.
- Monitor vendor and CERT/CC advisories for updated guidance and confirm the fixed build is deployed.
Detection
- Monitor iLDAP.exe for crash or restart events and correlate with inbound LDAP traffic spikes.
- Inspect LDAP traffic for messages with abnormally large tag lengths or malformed BER encoding.
- Alert on unexpected processes spawned by or network connections originating from the iLDAP service host.
- Review firewall and IDS logs for LDAP requests from untrusted external sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.idefense.com/application/poi/display?id=74 | |
| http://www.ipswitch.com/support/imail/releases/imail_professional/im805HF2.html | |
| http://www.kb.cert.org/vuls/id/972334 | Third Party AdvisoryUS Government Resource |
| http://www.osvdb.org/3984 | |
| http://www.securityfocus.com/bid/9682 | ExploitPatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/15243 | |
| http://www.idefense.com/application/poi/display?id=74 | |
| http://www.ipswitch.com/support/imail/releases/imail_professional/im805HF2.html | |
| http://www.kb.cert.org/vuls/id/972334 | Third Party AdvisoryUS Government Resource |
| http://www.osvdb.org/3984 | |
| http://www.securityfocus.com/bid/9682 | ExploitPatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/15243 |
Track CVE-2004-0297 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0297), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.