← Vulnerability feed

Vulnerability record · CVE-2008-1358 · published 17 March 2008

CVE-2008-1358: MDaemon IMAP Server Stack Buffer Overflow via FETCH BODY

Altn · Mdaemon

Alt-N MDaemon 9.6.4 contains a stack-based buffer overflow in its IMAP server, triggered by a FETCH command with an overly long BODY argument. A remote authenticated user can corrupt memory and potentially execute arbitrary code on the mail server.

6.5 CVSS 2.0 Medium EPSS 57% · top 1.0% CWE-119 · Memory buffer overflow
6.5CVSS 2.0 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a FETCH command with a long BODY.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityA network-reachable, authenticated buffer overflow with public exploit code and very high EPSS probability warrants prompt patching despite the medium CVSS v2 score.

What it is

Alt-N MDaemon 9.6.4 contains a stack-based buffer overflow in its IMAP server, triggered by a FETCH command with an overly long BODY argument. A remote authenticated user can corrupt memory and potentially execute arbitrary code on the mail server.

Impact

An attacker with valid IMAP credentials can crash the server or execute arbitrary code in the context of the MDaemon service, leading to full compromise of the mail server and its stored data.

Attack surface

Reachable over the network through the IMAP service (AV:N); the attacker must first authenticate to the IMAP server (Au:S), and no user interaction is required.

Exploitation

No CISA KEV listing and no ransomware association; EPSS is high at 0.57075 (99th percentile), and a public Exploit-DB entry (5248) exists, indicating exploit code is available.

What to do

  • Upgrade MDaemon to a version later than 9.6.4 that fixes the IMAP FETCH buffer overflow.
  • Restrict IMAP access to trusted networks and disable the service where it is not required.
  • Enforce strong, unique credentials and monitor for unusual IMAP authentication patterns.
  • Apply network filtering or an IMAP-aware proxy to reject malformed or oversized FETCH commands.

Detection

  • Monitor IMAP server logs for FETCH commands with abnormally long BODY arguments.
  • Watch for MDaemon process crashes or restarts correlated with IMAP sessions.
  • Alert on unexpected child processes or outbound connections originating from the MDaemon service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1358 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-27181Altn mdaemon cross-site request forgery vulnerabilityAn issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to …EPSS 0.65%8.8CVE-2021-27182Altn mdaemon injection vulnerabilityAn issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an…EPSS 1.6%7.2CVE-2021-27183Altn mdaemon vulnerabilityAn issue was discovered in MDaemon before 20.0.4. Administrators can use Remote Administration to exploit an Arbitrary File Write vulnerability. An a…EPSS 2.7%6.1CVE-2021-27180Altn mdaemon cross-site scripting vulnerabilityAn issue was discovered in MDaemon before 20.0.4. There is Reflected XSS in Webmail (aka WorldClient). It can be exploited via a GET request. It allo…EPSS 0.93%6.1CVE-2019-8983Altn mdaemon cross-site scripting vulnerabilityMDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2).EPSS 0.79%6.1CVE-2019-8984Altn mdaemon cross-site scripting vulnerabilityMDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2).EPSS 0.79%5.4CVE-2022-29975Altn mdaemon cross-site scripting vulnerabilityAn Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .EPSS 0.49%5.4CVE-2022-29976Altn mdaemon cross-site scripting vulnerabilityAn Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2008-1358), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.