Alt-N MDaemon Remote Status Command Buffer Overflow Vulnerability
BID:10366
Info
Alt-N MDaemon Remote Status Command Buffer Overflow Vulnerability
| Bugtraq ID: | 10366 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2004 12:00AM |
| Updated: | May 17 2004 12:00AM |
| Credit: | Discovery of this issue is credited to ned <[email protected]>. |
| Vulnerable: |
Altn MDaemon 6.8.5 Altn MDaemon 6.8.4 Altn MDaemon 6.8.3 Altn MDaemon 6.8.2 Altn MDaemon 6.8.1 Altn MDaemon 6.8 .0 Altn MDaemon 6.7.9 Altn MDaemon 6.7.5 Altn MDaemon 6.5.2 Altn MDaemon 6.5 .0 Altn MDaemon 6.0.7 Altn MDaemon 6.0.6 Altn MDaemon 6.0.5 Altn MDaemon 6.0 .0 Altn MDaemon 5.0.7 Altn MDaemon 3.5.6 Altn MDaemon 3.5.4 Altn MDaemon 3.5.1 Altn MDaemon 3.5 .0 Altn MDaemon 3.1.2 Altn MDaemon 3.1.1 Altn MDaemon 3.1 beta Altn MDaemon 3.0.4 Altn MDaemon 3.0.3 Altn MDaemon 2.71 SP1 Altn MDaemon 2.8.5 0 Altn MDaemon 2.8 |
| Not Vulnerable: | |
Discussion
Alt-N MDaemon Remote Status Command Buffer Overflow Vulnerability
Alt-N MDaemon is reportedly prone to a remote stack-based buffer overflow vulnerability. This vulnerability is due to a failure of the application to properly validate buffer sizes when processing input.
It should be noted that this issue can only be exploited by clients authenticated to the affected IMAP server; any user with an email account can leverage this issue.
This issue can be leveraged to cause the affected process to crash, denying service to legitimate users. It has been reported that this issue can also be leveraged to execute arbitrary code with the privileges of the user running the server on an affected computer.
Alt-N MDaemon is reportedly prone to a remote stack-based buffer overflow vulnerability. This vulnerability is due to a failure of the application to properly validate buffer sizes when processing input.
It should be noted that this issue can only be exploited by clients authenticated to the affected IMAP server; any user with an email account can leverage this issue.
This issue can be leveraged to cause the affected process to crash, denying service to legitimate users. It has been reported that this issue can also be leveraged to execute arbitrary code with the privileges of the user running the server on an affected computer.
Exploit / POC
Alt-N MDaemon Remote Status Command Buffer Overflow Vulnerability
It has been reported that an exploit implemented with the SMUDGE framework is available. This can be obtained at http://felinemenace.org
It has been reported that an exploit implemented with the SMUDGE framework is available. This can be obtained at http://felinemenace.org
Solution / Fix
Alt-N MDaemon Remote Status Command Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Alt-N MDaemon Remote Status Command Buffer Overflow Vulnerability
References:
References:
- Alt-N Homepage (Alt-N)