Impact
A heap-based buffer overflow occurs in hMailServer's legacy Blowfish encryption routine (BlowFishEncryptor::Encode) when handling passwords of certain lengths. The flaw allows an attacker with a mailbox account to trigger a service crash, leading to denial of service, and may enable further undisclosed exploits. The same overflow can be triggered by locally logged‑on users via a COM interface that performs Blowfish encryption without authentication, or by users writing stored secrets when ProtectStoredSecretsWithDPAPI is disabled.
Affected Systems
The vulnerability affects Progressive Robot Ltd's hMailServer version 6.0.0 through 6.3.5, inclusive. Versions 6.3.4 and 6.3.5 are particularly vulnerable when the self‑service REST API is enabled, as an authenticated user can execute the overflow remotely during the personal‑data export operation. Any local interactive user with access to the server can also exploit the issue via the Utilities.BlowfishEncrypt COM method if the application is not properly locked down.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires user authentication to the hMailServer mailbox or local interactive access to the server, and the attacker must configure password lengths between 129 and 247 characters that are not multiples of eight when the REST API is enabled. Once triggered, the overflow writes up to seven bytes beyond the 255‑byte buffer, causing the application to crash. The attacker can exploit the flaw remotely through the REST API or locally through the COM method, making it a credible threat to availability for affected installations.
OpenCVE Enrichment