← Vulnerability feed

Vulnerability record · CVE-2004-1638 · published 16 October 2004

CVE-2004-1638: MailCarrier SMTP EHLO/HELO buffer overflow allows remote code execution

MailCarrier 2.51 contains a buffer overflow triggered by an overly long EHLO command, and possibly a long HELO command. A remote attacker can send a crafted SMTP greeting to overflow the buffer and potentially execute arbitrary code on the mail server.

7.5 CVSS 2.0 High EPSS 63% · top 0.8%
7.5CVSS 2.0 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
0Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (2) HELO command.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote unauthenticated code execution with a high EPSS score and public exploit references, though the product is old and no KEV listing exists.

What it is

MailCarrier 2.51 contains a buffer overflow triggered by an overly long EHLO command, and possibly a long HELO command. A remote attacker can send a crafted SMTP greeting to overflow the buffer and potentially execute arbitrary code on the mail server.

Impact

An unauthenticated remote attacker could execute arbitrary code with the privileges of the MailCarrier service, leading to full compromise of the mail server. Even without reliable code execution, the overflow can crash the service, causing denial of service.

Attack surface

The flaw is reachable over the network through the SMTP service, as reflected by the AV:N vector, and requires no authentication or user interaction. The attacker only needs to connect to the SMTP port and issue a long EHLO (or HELO) command.

Exploitation

The record is not listed in CISA KEV, but EPSS is high at 0.62756 (99.1st percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code or proof-of-concept is available. No ransomware usage is documented.

What to do

  • Upgrade MailCarrier to a version later than 2.51 if the vendor has released a fix; the record does not name a patched version.
  • If no patch exists, restrict SMTP access to trusted networks and disable the service where not required.
  • Place the SMTP service behind a filtering proxy or IPS that rejects oversized EHLO/HELO commands.
  • Run the MailCarrier service with least privilege to limit the impact of code execution.

Detection

  • Monitor SMTP logs for unusually long EHLO or HELO commands or malformed greetings.
  • Alert on MailCarrier process crashes or restarts that correlate with inbound SMTP connections.
  • Use network IDS signatures for oversized SMTP command lines targeting port 25 or the configured MailCarrier port.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

References

Track CVE-2004-1638 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2004-1638), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.