Vulnerability record · CVE-2006-1255 · published 19 March 2006
CVE-2006-1255: Mercur Messaging IMAP stack buffer overflow via LOGIN or SELECT
Mercur · Mercur Messaging
Mercur Messaging 5.0 SP3 and earlier contains a stack-based buffer overflow in its IMAP service, triggered by a long string passed to the LOGIN or SELECT command. A remote, unauthenticated attacker can crash the service and possibly execute arbitrary code. The record notes these vectors differ from CVE-2003-1177, so it is treated as a separate issue.
Description
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string to the (1) LOGIN or (2) SELECT command, a different set of attack vectors and possibly a different vulnerability than CVE-2003-1177.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score is 10.0 with network reachability, no authentication, and full confidentiality, integrity, and availability impact, and public exploit references exist.
What it is
Mercur Messaging 5.0 SP3 and earlier contains a stack-based buffer overflow in its IMAP service, triggered by a long string passed to the LOGIN or SELECT command. A remote, unauthenticated attacker can crash the service and possibly execute arbitrary code. The record notes these vectors differ from CVE-2003-1177, so it is treated as a separate issue.
Impact
An attacker can cause a denial of service by crashing the IMAP service and may achieve arbitrary code execution in the context of the IMAP process. Successful code execution would give the attacker control over the mail server.
Attack surface
The flaw is reached over the network through the IMAP service, per the AV:N vector, and no authentication is required (Au:N). No user interaction is indicated by the description or vector.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at 0.6877 (99.3rd percentile) and a Secunia reference is tagged Exploit, indicating public exploit material exists.
What to do
- Apply the vendor patch or upgrade Mercur Messaging beyond 5.0 SP3 as soon as possible.
- If patching is not immediately possible, restrict IMAP access to trusted networks or IP ranges.
- Disable or block the IMAP service if it is not required.
- Place the IMAP service behind a filtering proxy or IPS that can drop oversized LOGIN and SELECT commands.
- Monitor vendor and Secunia advisories for updated guidance on this product.
Detection
- Inspect IMAP logs for LOGIN or SELECT commands containing unusually long argument strings.
- Alert on IMAP service crashes or unexpected restarts.
- Use network IDS signatures for oversized IMAP LOGIN and SELECT commands.
- Correlate repeated malformed IMAP requests from a single source IP.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-1255 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-1255), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.