Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to hMailServer 6.3.6, which also requires authentication for the COM Utilities helpers (6.3.4 is the first release with this routine fixed).
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account. | |
| Title | Heap-based Buffer Overflow in hMailServer | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-10-08T10:53:10.627Z
Reserved: 2026-09-29T21:04:45.349Z
Link: CVE-2026-103010
No data.
Status : Received
Published: 2026-10-08T11:16:42.117
Modified: 2026-10-08T11:16:42.117
Link: CVE-2026-103010
No data.
OpenCVE Enrichment
Updated: 2026-10-08T12:30:04Z
Weaknesses