Ipswitch IMail Server Multiple Buffer Overflow Denial Of Service Vulnerabilities
BID:11106
Info
Ipswitch IMail Server Multiple Buffer Overflow Denial Of Service Vulnerabilities
| Bugtraq ID: | 11106 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2004 12:00AM |
| Updated: | Sep 03 2004 12:00AM |
| Credit: | These vulnerabilities were disclosed by the vendor. |
| Vulnerable: |
Ipswitch IMail 8.1 Ipswitch IMail 8.0.5 Ipswitch IMail 8.0.3 Ipswitch IMail 7.12 Ipswitch IMail 7.1 Ipswitch IMail 7.0.7 Ipswitch IMail 7.0.6 Ipswitch IMail 7.0.5 Ipswitch IMail 7.0.4 Ipswitch IMail 7.0.3 Ipswitch IMail 7.0.2 Ipswitch IMail 7.0.1 Ipswitch IMail 6.4 Ipswitch IMail 6.3 Ipswitch IMail 6.2 Ipswitch IMail 6.1 Ipswitch IMail 6.0.6 Ipswitch IMail 6.0.5 Ipswitch IMail 6.0.4 Ipswitch IMail 6.0.3 Ipswitch IMail 6.0.2 Ipswitch IMail 6.0.1 Ipswitch IMail 6.0 Ipswitch IMail 5.0.8 Ipswitch IMail 5.0.7 Ipswitch IMail 5.0.6 Ipswitch IMail 5.0.5 Ipswitch IMail 5.0 |
| Not Vulnerable: |
Ipswitch IMail 8.13 |
Discussion
Ipswitch IMail Server Multiple Buffer Overflow Denial Of Service Vulnerabilities
It is reported that IMail is susceptible to multiple buffer overflow denial of service vulnerabilities.
These vulnerabilities allow a remote attacker to crash the affected application, denying service to legitimate users. It is conjectured that it may be possible for an attacker to execute arbitrary code in the context of the affected server application.
Versions of the application prior to 8.13 are reported affected by these vulnerabilities.
It is reported that IMail is susceptible to multiple buffer overflow denial of service vulnerabilities.
These vulnerabilities allow a remote attacker to crash the affected application, denying service to legitimate users. It is conjectured that it may be possible for an attacker to execute arbitrary code in the context of the affected server application.
Versions of the application prior to 8.13 are reported affected by these vulnerabilities.
Exploit / POC
Ipswitch IMail Server Multiple Buffer Overflow Denial Of Service Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Ipswitch IMail Server Multiple Buffer Overflow Denial Of Service Vulnerabilities
Solution:
The vendor has released version 8.13 to address these issues:
Ipswitch IMail 8.1
Solution:
The vendor has released version 8.13 to address these issues:
Ipswitch IMail 8.1
-
Ipswitch imail813.exe
ftp://ftp.ipswitch.com/Ipswitch/Product_Support/IMail/imail813.exe
References
Ipswitch IMail Server Multiple Buffer Overflow Denial Of Service Vulnerabilities
References:
References:
- IMail - Version 8.13 Release Notes (Ipswitch)
- IMail Patches & Upgrades (Ipswitch)
- IMail Server Homepage (Ipswitch)