Impact
hMailServer 6.0.0 through 6.3.5 processes various IMAP commands with quadratic time and memory complexity. Commands such as FETCH, SEARCH, SORT, and HEADER.FIELDS perform multiple passes over the input or the message, repeatedly copying data and comparing strings in a case‑insensitive manner. As a result a single signed‑in user can craft commands that consume memory out of proportion to the command size and halt the server’s I/O threads, causing the IMAP, SMTP, and POP3 services to stop responding.
Affected Systems
The vulnerability affects Progressive Robot Ltd’s hMailServer product in all releases from version 6.0.0 up to, but not including, 6.3.6. The official fix is available in hMailServer 6.3.6, which rewrites command parsing to perform single‑pass operations, limits memory usage per command, and rejects oversized FETCH instructions before any data is returned.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS is not available and the flaw is not listed in CISA’s KEV catalog, so it is currently considered a lower exploitation probability. However, the attack requires a valid signed‑in account, and the shared worker pool means that a single malicious user can cause a denial of service across all mail protocols. The vendor solution is to upgrade to 6.3.6; otherwise restricting IMAP access to trusted accounts and networks can reduce the attack surface.
OpenCVE Enrichment