Ipswitch Collaboration Suite 2 Hotfix 2

Date released: May 26, 2005

Download:

http://ftp.ipswitch.com/ipswitch/Product_Support/ICS/ICS2hf2.exe

Summary:

The Following security vulnerabilities were found and fixed with the help of iDEFENSE, Inc. For more information see http://idefense.com.

  • IMAP4d32: Fixed crash when malicious LSUB encountered.
  • IMAP4D32: Fixed crash when SELECTing mailbox name with close to 256 characters.
  • IMAP4D32: Fixed crash when LOGIN userid was excessively long.
  • IMAP4D32: Fixed crash when STATUS mailbox name was excessively long.
  • SMTPD32: Fixed bug causing corruption of attached files.
  • QUEUEMGR: Fixed bug causing log information to be saved to wrong file.
  • Web Calendaring: Removed vulnerability whereby user could read server files using ....\ in GET.
  • IM Server: Fixed potential crash due to TCP/IP attack

Requirements:

  • You must be running Ipswitch Collaboration Suite 2 to install this patch

How to update to version 2 to Hotfix 2:

  1. Print this page as a reference during the installation process.
  2. Download the file ICS2hf2.exe by clicking on the link under the Download section above and save the file to your hard drive. We recommend saving the file to your Desktop as it will be easier to locate.
  3. Locate the ICS2hf2.exe file and double-click it to start the installation process.
  4. Follow the prompts on your screen.