Vulnerability record · CVE-2008-1358 · published 17 March 2008
CVE-2008-1358: MDaemon IMAP Server Stack Buffer Overflow via FETCH BODY
Altn · Mdaemon
Alt-N MDaemon 9.6.4 contains a stack-based buffer overflow in its IMAP server, triggered by a FETCH command with an overly long BODY argument. A remote authenticated user can corrupt memory and potentially execute arbitrary code on the mail server.
Description
Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a FETCH command with a long BODY.
AV:N/AC:L/Au:S/C:P/I:P/A:P
Automated analysis
high priorityA network-reachable, authenticated buffer overflow with public exploit code and very high EPSS probability warrants prompt patching despite the medium CVSS v2 score.
What it is
Alt-N MDaemon 9.6.4 contains a stack-based buffer overflow in its IMAP server, triggered by a FETCH command with an overly long BODY argument. A remote authenticated user can corrupt memory and potentially execute arbitrary code on the mail server.
Impact
An attacker with valid IMAP credentials can crash the server or execute arbitrary code in the context of the MDaemon service, leading to full compromise of the mail server and its stored data.
Attack surface
Reachable over the network through the IMAP service (AV:N); the attacker must first authenticate to the IMAP server (Au:S), and no user interaction is required.
Exploitation
No CISA KEV listing and no ransomware association; EPSS is high at 0.57075 (99th percentile), and a public Exploit-DB entry (5248) exists, indicating exploit code is available.
What to do
- Upgrade MDaemon to a version later than 9.6.4 that fixes the IMAP FETCH buffer overflow.
- Restrict IMAP access to trusted networks and disable the service where it is not required.
- Enforce strong, unique credentials and monitor for unusual IMAP authentication patterns.
- Apply network filtering or an IMAP-aware proxy to reject malformed or oversized FETCH commands.
Detection
- Monitor IMAP server logs for FETCH commands with abnormally long BODY arguments.
- Watch for MDaemon process crashes or restarts correlated with IMAP sessions.
- Alert on unexpected child processes or outbound connections originating from the MDaemon service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-1358 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-1358), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.