Ipswitch IMail Server Delete Command Remote Buffer Overflow Vulnerability
BID:11675
Info
Ipswitch IMail Server Delete Command Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11675 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2004 12:00AM |
| Updated: | Nov 13 2004 12:00AM |
| Credit: | Discovery is credited to Muts. |
| Vulnerable: |
Ipswitch IMail 8.13 |
| Not Vulnerable: |
Ipswitch IMail 8.14 |
Discussion
Ipswitch IMail Server Delete Command Remote Buffer Overflow Vulnerability
Ipswitch IMail is reported prone to a remote buffer overflow vulnerability. This issue exists due to insufficient boundary checks performed by the application. Exploitation of this issue can allow a remote attacker to execute arbitrary code on a vulnerable computer to gain unauthorized access.
Ipswitch IMail 8.13 is reported prone to this vulnerability. It is possible that other versions are affected as well.
Ipswitch IMail is reported prone to a remote buffer overflow vulnerability. This issue exists due to insufficient boundary checks performed by the application. Exploitation of this issue can allow a remote attacker to execute arbitrary code on a vulnerable computer to gain unauthorized access.
Ipswitch IMail 8.13 is reported prone to this vulnerability. It is possible that other versions are affected as well.
Exploit / POC
Ipswitch IMail Server Delete Command Remote Buffer Overflow Vulnerability
An exploit has been released as part of the MetaSploit Framework 2.3.
An exploit by Zatlander is available:
An exploit has been released as part of the MetaSploit Framework 2.3.
An exploit by Zatlander is available:
Solution / Fix
Ipswitch IMail Server Delete Command Remote Buffer Overflow Vulnerability
Solution:
The vendor has released a patch that can be applied against 8.1x versions to resolve this vulnerability.
Ipswitch IMail 8.13
Solution:
The vendor has released a patch that can be applied against 8.1x versions to resolve this vulnerability.
Ipswitch IMail 8.13
-
Ipswitch imail814.exe
ftp://ftp.ipswitch.com/Ipswitch/Product_Support/IMail/imail814.exe
References
Ipswitch IMail Server Delete Command Remote Buffer Overflow Vulnerability
References:
References:
- IMail Home Page (Ipswitch)
- IMail Server 8.14 Patch (IPSwitch)
- IPSwitch-IMail-8.13 Stack Overflow in the DELETE Command ("Jérôme" ATHIAS
)