Up-IMAPProxy Multiple Remote Vulnerabilities
BID:11630
Info
Up-IMAPProxy Multiple Remote Vulnerabilities
| Bugtraq ID: | 11630 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2004 12:00AM |
| Updated: | Nov 08 2004 12:00AM |
| Credit: | Discovery of these vulnerabilities is credited to Timo Sirainen <[email protected]>. |
| Vulnerable: |
up-imapproxy up-imapproxy 1.2.2 up-imapproxy up-imapproxy |
| Not Vulnerable: | |
Discussion
Up-IMAPProxy Multiple Remote Vulnerabilities
up-imapproxy is reported prone to multiple remote vulnerabilities. The following specific issues are reported:
It is reported that multiple denial of service conditions exist in the way up-imapproxy handles literal values. Literal data processed by affected functions will result in a denial of service. Additionally, a literal value passed as a command to the affected service will result in a denial of service if the command does not exist.
A remote attacker may exploit these vulnerabilities to crash the affected service effectively denying service to legitimate users.
Finally, it is reported that literal value sizes are stored in signed integer format. The discoverer of these vulnerabilities reports that this may result in a boundary condition on 64-bit platforms.
A remote attacker may potentially exploit this condition to reveal potentially sensitive data.
It should be noted that reports indicate that up-imapproxy may not actually execute on 64-bit platforms.
up-imapproxy is reported prone to multiple remote vulnerabilities. The following specific issues are reported:
It is reported that multiple denial of service conditions exist in the way up-imapproxy handles literal values. Literal data processed by affected functions will result in a denial of service. Additionally, a literal value passed as a command to the affected service will result in a denial of service if the command does not exist.
A remote attacker may exploit these vulnerabilities to crash the affected service effectively denying service to legitimate users.
Finally, it is reported that literal value sizes are stored in signed integer format. The discoverer of these vulnerabilities reports that this may result in a boundary condition on 64-bit platforms.
A remote attacker may potentially exploit this condition to reveal potentially sensitive data.
It should be noted that reports indicate that up-imapproxy may not actually execute on 64-bit platforms.
Exploit / POC
Up-IMAPProxy Multiple Remote Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Up-IMAPProxy Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Up-IMAPProxy Multiple Remote Vulnerabilities
References:
References:
- up-imapproxy Homepage (up-imapproxy)
- up-imapproxy DoS vulnerabilities (Timo Sirainen
)