Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade to hMailServer 6.3.6, which also requires authentication for the COM Utilities helpers (6.3.4 is the first release with this routine fixed).
Workaround
No workaround given by the vendor.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account. | |
| Title | Heap-based Buffer Overflow in hMailServer | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-10-08T14:22:28.966Z
Reserved: 2026-09-29T21:04:45.349Z
Link: CVE-2026-103010
Updated: 2026-10-08T14:22:24.964Z
Status : Received
Published: 2026-10-08T11:16:42.117
Modified: 2026-10-08T15:17:31.233
Link: CVE-2026-103010
No data.
OpenCVE Enrichment
Updated: 2026-10-08T12:30:04Z