Ipswitch IMail Server Multiple Vulnerabilities
BID:13727
Info
Ipswitch IMail Server Multiple Vulnerabilities
| Bugtraq ID: | 13727 |
| Class: | Unknown |
| CVE: |
CVE-2005-1256 CVE-2005-1249 CVE-2005-1255 CVE-2005-1252 CVE-2005-1254 |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2005 12:00AM |
| Updated: | Apr 03 2007 03:12AM |
| Credit: | Sebastian Apelt is credited with the discovery of one the denial of service issues. iDEFENSE Labs also discovered a denial of service issue. The rest of the issues were discovered by anonymous researchers. |
| Vulnerable: |
Ipswitch IMail 8.15 Hotfix 1 Ipswitch IMail 8.14 Ipswitch IMail 8.13 Ipswitch IMail 8.2 Ipswitch IMail 8.1 Ipswitch IMail 8.0.5 Ipswitch IMail 8.0.3 Ipswitch IMail 7.12 Ipswitch IMail 7.1 Ipswitch IMail 7.0.7 Ipswitch IMail 7.0.6 Ipswitch IMail 7.0.5 Ipswitch IMail 7.0.4 Ipswitch IMail 7.0.3 Ipswitch IMail 7.0.2 Ipswitch IMail 7.0.1 Ipswitch IMail 6.4 Ipswitch IMail 6.3 Ipswitch IMail 6.2 Ipswitch IMail 6.1 Ipswitch IMail 6.0.6 Ipswitch IMail 6.0.5 Ipswitch IMail 6.0.4 Ipswitch IMail 6.0.3 Ipswitch IMail 6.0.2 Ipswitch IMail 6.0.1 Ipswitch IMail 6.0 Ipswitch IMail 5.0.8 Ipswitch IMail 5.0.7 Ipswitch IMail 5.0.6 Ipswitch IMail 5.0.5 Ipswitch IMail 5.0 |
| Not Vulnerable: |
Ipswitch IMail 8.2 Hotfix 2 |
Discussion
Ipswitch IMail Server Multiple Vulnerabilities
Ipswitch IMail is prone to multiple remote vulnerabilities. Attackers may exploit these issues to deny service for legitimate users, obtaoin potentially sensitive information, and execute arbitrary code.
The vulnerabilities include a directory-traversal issue, two remote denial-of-service issues, and multiple buffer-overflow issues.
Ipswitch IMail is prone to multiple remote vulnerabilities. Attackers may exploit these issues to deny service for legitimate users, obtaoin potentially sensitive information, and execute arbitrary code.
The vulnerabilities include a directory-traversal issue, two remote denial-of-service issues, and multiple buffer-overflow issues.
Exploit / POC
Ipswitch IMail Server Multiple Vulnerabilities
The following proof of concept for the directory-traversal issue is available:
GET /bla.jsp?\..\..\..\..\..\..\..\..\..\..\boot.ini HTTP/1.0
An exploit targeting the 'username' parameter of the LOGIN command has been provided by <[email protected]>.
Another exploit (imail.pl) targeting the LOGIN command has been provided by kcope.
An exploit (13727.c) targeted the LOGIN command is available by Heretic2.
The following proof of concept for the directory-traversal issue is available:
GET /bla.jsp?\..\..\..\..\..\..\..\..\..\..\boot.ini HTTP/1.0
An exploit targeting the 'username' parameter of the LOGIN command has been provided by <[email protected]>.
Another exploit (imail.pl) targeting the LOGIN command has been provided by kcope.
An exploit (13727.c) targeted the LOGIN command is available by Heretic2.
Solution / Fix
Ipswitch IMail Server Multiple Vulnerabilities
Solution:
The vendor has released a fix to address these issues.
Ipswitch IMail 8.2
Solution:
The vendor has released a fix to address these issues.
Ipswitch IMail 8.2
-
Ipswitch imail82hf2.exe
ftp://ftp.ipswitch.com/Ipswitch/Product_Support/IMail/imail82hf2.exe
References
Ipswitch IMail Server Multiple Vulnerabilities
References:
References:
- IMail Home Page (Ipswitch)
- IMail Server 8.2 Hotfix 2 (IPSwitch)
- Ipswitch IMail IMAP LOGIN Remote Buffer Overflow Vulnerabilities (iDEFENSE Labs
) - Ipswitch IMail IMAP LSUB DoS Vulnerability (iDEFENSE Labs
) - Ipswitch IMail IMAP SELECT Command DoS Vulnerability (iDEFENSE Labs
) - Ipswitch IMail IMAP STATUS Remote Buffer Overflow Vulnerability (iDEFENSE Labs
) - Ipswitch IMail Web Calendaring Arbitrary File Read Vulnerability (iDEFENSE Labs
)