Alt-N MDaemon IMAP/SMTP Server Multiple Remote Buffer Overflow Vulnerabilities
BID:11238
Info
Alt-N MDaemon IMAP/SMTP Server Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 11238 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2004 12:00AM |
| Updated: | Sep 22 2004 12:00AM |
| Credit: | Discovery of these vulnerabilities is credited to SecurityLab.RU. |
| Vulnerable: |
Alt-N MDaemon 6.5.1 |
| Not Vulnerable: | |
Discussion
Alt-N MDaemon IMAP/SMTP Server Multiple Remote Buffer Overflow Vulnerabilities
Alt-N MDaemon is reportedly prone to multiple remote buffer overflow vulnerabilities. The vulnerabilities are likely due to a failure of the application to properly validate buffer sizes when processing command argument input.
By sending a large argument to certain SMTP commands or an IMAP command it is possible to cause this issue to present itself. Apparently, the application will not validate the size of the input before copying it into a finite buffer in process memory.
These issues can be leveraged to cause the affected process to crash, denying service to legitimate users. It is conjectured that these issues can also be leveraged to execute arbitrary code with the privileges of the user running the server on an affected computer.
Alt-N MDaemon is reportedly prone to multiple remote buffer overflow vulnerabilities. The vulnerabilities are likely due to a failure of the application to properly validate buffer sizes when processing command argument input.
By sending a large argument to certain SMTP commands or an IMAP command it is possible to cause this issue to present itself. Apparently, the application will not validate the size of the input before copying it into a finite buffer in process memory.
These issues can be leveraged to cause the affected process to crash, denying service to legitimate users. It is conjectured that these issues can also be leveraged to execute arbitrary code with the privileges of the user running the server on an affected computer.
Exploit / POC
Alt-N MDaemon IMAP/SMTP Server Multiple Remote Buffer Overflow Vulnerabilities
The following proof of concept denial of service exploits are available:
The following proof of concept denial of service exploits are available:
Solution / Fix
Alt-N MDaemon IMAP/SMTP Server Multiple Remote Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Alt-N MDaemon IMAP/SMTP Server Multiple Remote Buffer Overflow Vulnerabilities
References:
References: