MailEnable IMAP Service Multiple Remote Pre-Authentication Buffer Overflow Vulnerabilities
BID:11755
Info
MailEnable IMAP Service Multiple Remote Pre-Authentication Buffer Overflow Vulnerabilities
| Bugtraq ID: | 11755 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2004 12:00AM |
| Updated: | Nov 25 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Nima Majidi <[email protected]>. |
| Vulnerable: |
MailEnable MailEnable Professional 1.116 MailEnable MailEnable Professional 1.115 MailEnable MailEnable Professional 1.114 MailEnable MailEnable Professional 1.113 MailEnable MailEnable Professional 1.112 MailEnable MailEnable Professional 1.111 MailEnable MailEnable Professional 1.110 MailEnable MailEnable Professional 1.109 MailEnable MailEnable Professional 1.108 MailEnable MailEnable Professional 1.107 MailEnable MailEnable Professional 1.106 MailEnable MailEnable Professional 1.105 MailEnable MailEnable Professional 1.104 MailEnable MailEnable Professional 1.103 MailEnable MailEnable Professional 1.102 MailEnable MailEnable Professional 1.101 MailEnable MailEnable Professional 1.52 MailEnable MailEnable Professional 1.51 MailEnable MailEnable Professional 1.19 MailEnable MailEnable Professional 1.18 MailEnable MailEnable Professional 1.17 MailEnable MailEnable Professional 1.16 MailEnable MailEnable Professional 1.15 MailEnable MailEnable Professional 1.14 MailEnable MailEnable Professional 1.13 MailEnable MailEnable Professional 1.12 MailEnable MailEnable Professional 1.5 MailEnable MailEnable Professional 1.2 a MailEnable MailEnable Professional 1.2 a MailEnable MailEnable Professional 1.2 MailEnable MailEnable Professional 1.2 MailEnable MailEnable Professional 1.1 MailEnable MailEnable Professional 1.0 017 MailEnable MailEnable Professional 1.0 016 MailEnable MailEnable Professional 1.0 015 MailEnable MailEnable Professional 1.0 014 MailEnable MailEnable Professional 1.0 013 MailEnable MailEnable Professional 1.0 012 MailEnable MailEnable Professional 1.0 011 MailEnable MailEnable Professional 1.0 010 MailEnable MailEnable Professional 1.0 009 MailEnable MailEnable Professional 1.0 008 MailEnable MailEnable Professional 1.0 007 MailEnable MailEnable Professional 1.0 006 MailEnable MailEnable Professional 1.0 005 MailEnable MailEnable Professional 1.0 004 MailEnable MailEnable Enterprise Edition 1.0 1 |
| Not Vulnerable: | |
Discussion
MailEnable IMAP Service Multiple Remote Pre-Authentication Buffer Overflow Vulnerabilities
MailEnable IMAP service is reported prone to multiple remote buffer overflow vulnerabilities. The following individual issues are reported:
The first buffer overflow vulnerability is reported to exist due to a lack of sufficient bounds checking performed on IMAP command arguments before the argument is copied into a finite process memory buffer.
A remote attacker may exploit this vulnerability prior to authentication to execute arbitrary code in the context of the affected service.
The second buffer overflow vulnerability presents itself due to a lack of boundary checks performed on request data sent to the IMAP service.
A remote attacker may exploit this vulnerability prior to authentication to execute arbitrary code in the context of the affected service.
MailEnable IMAP service is reported prone to multiple remote buffer overflow vulnerabilities. The following individual issues are reported:
The first buffer overflow vulnerability is reported to exist due to a lack of sufficient bounds checking performed on IMAP command arguments before the argument is copied into a finite process memory buffer.
A remote attacker may exploit this vulnerability prior to authentication to execute arbitrary code in the context of the affected service.
The second buffer overflow vulnerability presents itself due to a lack of boundary checks performed on request data sent to the IMAP service.
A remote attacker may exploit this vulnerability prior to authentication to execute arbitrary code in the context of the affected service.
Exploit / POC
MailEnable IMAP Service Multiple Remote Pre-Authentication Buffer Overflow Vulnerabilities
The following exploit is available:
The following exploit is available:
Solution / Fix
MailEnable IMAP Service Multiple Remote Pre-Authentication Buffer Overflow Vulnerabilities
Solution:
It is reported that the vendor has released a fix for this vulnerability. This fix does not appear to be available at the time of writing. Reports indicate that the fix will be available at the following location:
http://mailenable.com/hotfix.asp
Customers are advised to contact the vendor for further details in regards to obtaining and applying appropriate updates
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that the vendor has released a fix for this vulnerability. This fix does not appear to be available at the time of writing. Reports indicate that the fix will be available at the following location:
http://mailenable.com/hotfix.asp
Customers are advised to contact the vendor for further details in regards to obtaining and applying appropriate updates
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MailEnable IMAP Service Multiple Remote Pre-Authentication Buffer Overflow Vulnerabilities
References:
References:
- MailEnable Homepage (MailEnable)
- MailEnable Hotfix Page (MailEnable)