Vulnerability record · CVE-2004-1638 · published 16 October 2004
CVE-2004-1638: MailCarrier SMTP EHLO/HELO buffer overflow allows remote code execution
MailCarrier 2.51 contains a buffer overflow triggered by an overly long EHLO command, and possibly a long HELO command. A remote attacker can send a crafted SMTP greeting to overflow the buffer and potentially execute arbitrary code on the mail server.
Description
Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (2) HELO command.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with a high EPSS score and public exploit references, though the product is old and no KEV listing exists.
What it is
MailCarrier 2.51 contains a buffer overflow triggered by an overly long EHLO command, and possibly a long HELO command. A remote attacker can send a crafted SMTP greeting to overflow the buffer and potentially execute arbitrary code on the mail server.
Impact
An unauthenticated remote attacker could execute arbitrary code with the privileges of the MailCarrier service, leading to full compromise of the mail server. Even without reliable code execution, the overflow can crash the service, causing denial of service.
Attack surface
The flaw is reachable over the network through the SMTP service, as reflected by the AV:N vector, and requires no authentication or user interaction. The attacker only needs to connect to the SMTP port and issue a long EHLO (or HELO) command.
Exploitation
The record is not listed in CISA KEV, but EPSS is high at 0.62756 (99.1st percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code or proof-of-concept is available. No ransomware usage is documented.
What to do
- Upgrade MailCarrier to a version later than 2.51 if the vendor has released a fix; the record does not name a patched version.
- If no patch exists, restrict SMTP access to trusted networks and disable the service where not required.
- Place the SMTP service behind a filtering proxy or IPS that rejects oversized EHLO/HELO commands.
- Run the MailCarrier service with least privilege to limit the impact of code execution.
Detection
- Monitor SMTP logs for unusually long EHLO or HELO commands or malformed greetings.
- Alert on MailCarrier process crashes or restarts that correlate with inbound SMTP connections.
- Use network IDS signatures for oversized SMTP command lines targeting port 25 or the configured MailCarrier port.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
References
| Link | Tags |
|---|---|
| http://marc.info/?l=bugtraq&m=109880961630050&w=2 | |
| http://secunia.com/advisories/12999 | Vendor Advisory |
| http://www.securityfocus.com/bid/11535 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/17861 | |
| http://marc.info/?l=bugtraq&m=109880961630050&w=2 | |
| http://secunia.com/advisories/12999 | Vendor Advisory |
| http://www.securityfocus.com/bid/11535 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/17861 |
Track CVE-2004-1638 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2004-1638), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.