MailEnable HTTP Authorization Buffer Overflow Vulnerability
BID:13350
Info
MailEnable HTTP Authorization Buffer Overflow Vulnerability
| Bugtraq ID: | 13350 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2005 12:00AM |
| Updated: | Apr 25 2005 12:00AM |
| Credit: | Discovered by CorryL <[email protected]>. |
| Vulnerable: |
MailEnable MailEnable Professional 1.116 MailEnable MailEnable Professional 1.115 MailEnable MailEnable Professional 1.114 MailEnable MailEnable Professional 1.113 MailEnable MailEnable Professional 1.112 MailEnable MailEnable Professional 1.111 MailEnable MailEnable Professional 1.110 MailEnable MailEnable Professional 1.109 MailEnable MailEnable Professional 1.108 MailEnable MailEnable Professional 1.107 MailEnable MailEnable Professional 1.106 MailEnable MailEnable Professional 1.105 MailEnable MailEnable Professional 1.104 MailEnable MailEnable Professional 1.103 MailEnable MailEnable Professional 1.102 MailEnable MailEnable Professional 1.101 MailEnable MailEnable Professional 1.54 MailEnable MailEnable Professional 1.53 MailEnable MailEnable Professional 1.52 MailEnable MailEnable Professional 1.51 MailEnable MailEnable Professional 1.19 MailEnable MailEnable Professional 1.18 MailEnable MailEnable Professional 1.17 MailEnable MailEnable Professional 1.16 MailEnable MailEnable Professional 1.15 MailEnable MailEnable Professional 1.14 MailEnable MailEnable Professional 1.13 MailEnable MailEnable Professional 1.12 MailEnable MailEnable Professional 1.5 MailEnable MailEnable Professional 1.2 a MailEnable MailEnable Professional 1.2 MailEnable MailEnable Professional 1.1 MailEnable MailEnable Professional 1.0 017 MailEnable MailEnable Professional 1.0 016 MailEnable MailEnable Professional 1.0 015 MailEnable MailEnable Professional 1.0 014 MailEnable MailEnable Professional 1.0 013 MailEnable MailEnable Professional 1.0 012 MailEnable MailEnable Professional 1.0 011 MailEnable MailEnable Professional 1.0 010 MailEnable MailEnable Professional 1.0 009 MailEnable MailEnable Professional 1.0 008 MailEnable MailEnable Professional 1.0 007 MailEnable MailEnable Professional 1.0 006 MailEnable MailEnable Professional 1.0 005 MailEnable MailEnable Professional 1.0 004 MailEnable MailEnable Enterprise Edition 1.0 4 MailEnable MailEnable Enterprise Edition 1.0 3 MailEnable MailEnable Enterprise Edition 1.0 2 MailEnable MailEnable Enterprise Edition 1.0 1 MailEnable MailEnable Enterprise Edition 1.0 |
| Not Vulnerable: | |
Discussion
MailEnable HTTP Authorization Buffer Overflow Vulnerability
MailEnable is prone to a remotely exploitable buffer overflow vulnerability. This issue occurs in the server's HTTP Header Field Definitions.
This condition may be leveraged to overwrite sensitive program control variables, allowing a remote attacker to control execution flow of the server process.
MailEnable is prone to a remotely exploitable buffer overflow vulnerability. This issue occurs in the server's HTTP Header Field Definitions.
This condition may be leveraged to overwrite sensitive program control variables, allowing a remote attacker to control execution flow of the server process.
Exploit / POC
MailEnable HTTP Authorization Buffer Overflow Vulnerability
An exploit (mailenable_auth_header.pm) is available for the Metasploit Framework.
The following proof of concept exploit is available:
An exploit (mailenable_auth_header.pm) is available for the Metasploit Framework.
The following proof of concept exploit is available:
Solution / Fix
MailEnable HTTP Authorization Buffer Overflow Vulnerability
Solution:
A fix for this issue is reportedly available, however, Symantec was unable to confirm this. Users should contact the software vendor to determine the availability of fixed packages.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
A fix for this issue is reportedly available, however, Symantec was unable to confirm this. Users should contact the software vendor to determine the availability of fixed packages.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MailEnable HTTP Authorization Buffer Overflow Vulnerability
References:
References:
- MailEnable Homepage (MailEnable)
- MailEnable Hotfix Page (MailEnable)
- MailEnable HTTPS Buffer Overflow [x0n3-h4ck] ("CorryL"
)