MailEnable Content-Length Denial Of Service Vulnerability
BID:10838
Info
MailEnable Content-Length Denial Of Service Vulnerability
| Bugtraq ID: | 10838 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2004 12:00AM |
| Updated: | Aug 02 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to "CoolICE" <[email protected]>. |
| Vulnerable: |
MailEnable MailEnable Professional 1.19 MailEnable MailEnable Professional 1.18 MailEnable MailEnable Professional 1.17 MailEnable MailEnable Professional 1.16 MailEnable MailEnable Professional 1.15 MailEnable MailEnable Professional 1.14 MailEnable MailEnable Professional 1.13 MailEnable MailEnable Professional 1.12 MailEnable MailEnable Professional 1.1 |
| Not Vulnerable: | |
Discussion
MailEnable Content-Length Denial Of Service Vulnerability
MailEnable is reported prone to a remote denial of service vulnerability. This vulnerability is reported to exist in the MailEnable HTTP header parsing code.
When reading a large content-length header field from an HTTP request, the operation overflows a fixed size memory buffer and the HTTP service will reportedly crash.
The vulnerability can be exploited to crash the affected HTTP service, denying service to legitimate users. The possibility to execute arbitrary code may also be present.
MailEnable is reported prone to a remote denial of service vulnerability. This vulnerability is reported to exist in the MailEnable HTTP header parsing code.
When reading a large content-length header field from an HTTP request, the operation overflows a fixed size memory buffer and the HTTP service will reportedly crash.
The vulnerability can be exploited to crash the affected HTTP service, denying service to legitimate users. The possibility to execute arbitrary code may also be present.
Exploit / POC
MailEnable Content-Length Denial Of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
MailEnable Content-Length Denial Of Service Vulnerability
Solution:
The vendor has released a hotfix to address this issue:
MailEnable MailEnable Professional 1.1
MailEnable MailEnable Professional 1.12
MailEnable MailEnable Professional 1.13
MailEnable MailEnable Professional 1.14
MailEnable MailEnable Professional 1.15
MailEnable MailEnable Professional 1.16
MailEnable MailEnable Professional 1.17
MailEnable MailEnable Professional 1.18
MailEnable MailEnable Professional 1.19
Solution:
The vendor has released a hotfix to address this issue:
MailEnable MailEnable Professional 1.1
-
MailEnable MEHTTPS.zip
http://www.mailenable.com/hotfix/MEHTTPS.zip
MailEnable MailEnable Professional 1.12
-
MailEnable MEHTTPS.zip
http://www.mailenable.com/hotfix/MEHTTPS.zip
MailEnable MailEnable Professional 1.13
-
MailEnable MEHTTPS.zip
http://www.mailenable.com/hotfix/MEHTTPS.zip
MailEnable MailEnable Professional 1.14
-
MailEnable MEHTTPS.zip
http://www.mailenable.com/hotfix/MEHTTPS.zip
MailEnable MailEnable Professional 1.15
-
MailEnable MEHTTPS.zip
http://www.mailenable.com/hotfix/MEHTTPS.zip
MailEnable MailEnable Professional 1.16
-
MailEnable MEHTTPS.zip
http://www.mailenable.com/hotfix/MEHTTPS.zip
MailEnable MailEnable Professional 1.17
-
MailEnable MEHTTPS.zip
http://www.mailenable.com/hotfix/MEHTTPS.zip
MailEnable MailEnable Professional 1.18
-
MailEnable MEHTTPS.zip
http://www.mailenable.com/hotfix/MEHTTPS.zip
MailEnable MailEnable Professional 1.19
-
MailEnable MEHTTPS.zip
http://www.mailenable.com/hotfix/MEHTTPS.zip
References
MailEnable Content-Length Denial Of Service Vulnerability
References:
References:
- MailEnable Homepage (MailEnable)
- DOS@MEHTTPS ("CoolICE"
) - RE: [Full-Disclosure] DOS@MEHTTPS ("Peter Fregon"
)