Mercury Mail Multiple Remote IMAP Stack Buffer Overflow Vulnerabilities
BID:11775
Info
Mercury Mail Multiple Remote IMAP Stack Buffer Overflow Vulnerabilities
| Bugtraq ID: | 11775 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1211 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2004 12:00AM |
| Updated: | Mar 26 2007 07:53PM |
| Credit: | Muts disclosed this vulnerability. Further disclosure was provided by Reed Arvin <[email protected]>. |
| Vulnerable: |
David Harris Mercury (win32 version) 4.0 1a David Harris Mercury (win32 version) 4.0 1 |
| Not Vulnerable: |
David Harris Mercury (win32 version) 4.0 1b |
Discussion
Mercury Mail Multiple Remote IMAP Stack Buffer Overflow Vulnerabilities
Mercury Mail is reported susceptible to multiple stack-based buffer-overflow vulnerabilities in its IMAP server implementation. These issues are due to the application's failure to properly bounds-check user-supplied input before copying it to a finite-sized memory buffer.
Exploiting these vulnerabilities allows authenticated, remote attackers to execute arbitrary machine code in the context of the affected server process.
Versions prior to 4.01a of Mercury Mail are reported affected by these vulnerabilities; other versions may also be affected.
Note: BID 11788 has been consolidated with this BID; they actually represent the same issues.
Mercury Mail is reported susceptible to multiple stack-based buffer-overflow vulnerabilities in its IMAP server implementation. These issues are due to the application's failure to properly bounds-check user-supplied input before copying it to a finite-sized memory buffer.
Exploiting these vulnerabilities allows authenticated, remote attackers to execute arbitrary machine code in the context of the affected server process.
Versions prior to 4.01a of Mercury Mail are reported affected by these vulnerabilities; other versions may also be affected.
Note: BID 11788 has been consolidated with this BID; they actually represent the same issues.
Exploit / POC
Mercury Mail Multiple Remote IMAP Stack Buffer Overflow Vulnerabilities
The following exploits are available:
The following exploits are available:
- /data/vulnerabilities/exploits/mercury_imap.pm
- /data/vulnerabilities/exploits/ex_MERCURY2.c
- /data/vulnerabilities/exploits/mercury_imap.c
- /data/vulnerabilities/exploits/mercury_imap.pm
- /data/vulnerabilities/exploits/mercury.py
- /data/vulnerabilities/exploits/ex_MERCURY.c
- /data/vulnerabilities/exploits/11775-mercury.pl
Solution / Fix
Mercury Mail Multiple Remote IMAP Stack Buffer Overflow Vulnerabilities
Solution:
The vendor has released version 4.01b to address these issues.
David Harris Mercury (win32 version) 4.0 1
David Harris Mercury (win32 version) 4.0 1a
Solution:
The vendor has released version 4.01b to address these issues.
David Harris Mercury (win32 version) 4.0 1
-
David Harris m32-401b.zip
ftp://ftp.usm.maine.edu/pegasus/mercury32/m32-401b.zip
David Harris Mercury (win32 version) 4.0 1a
-
David Harris m32-401b.zip
ftp://ftp.usm.maine.edu/pegasus/mercury32/m32-401b.zip
References
Mercury Mail Multiple Remote IMAP Stack Buffer Overflow Vulnerabilities
References:
References:
- MERCURY /32: Changes and additions for version 4.01b (David Harris)
- MERCURY MAIL TRANSPORT AGENT FOR 32BITS WINDOWS AND NOVELL. (David Harris)
- Mercury MTA Overview (David Harris)
- Multiple buffer overflows exist in Mercury/32, v4.01a, Dec 8 2003. (Reed Arvin
)