MailEnable IMAP SELECT Request Buffer Overflow Vulnerability
BID:14243
Info
MailEnable IMAP SELECT Request Buffer Overflow Vulnerability
| Bugtraq ID: | 14243 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-2278 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to Ariel Sanchez from Core Security Technologies. |
| Vulnerable: |
MailEnable MailEnable Professional 1.54 MailEnable MailEnable Professional 1.53 MailEnable MailEnable Professional 1.52 MailEnable MailEnable Professional 1.51 MailEnable MailEnable Professional 1.5 MailEnable MailEnable Enterprise Edition 1.0 4 MailEnable MailEnable Enterprise Edition 1.0 3 MailEnable MailEnable Enterprise Edition 1.0 2 MailEnable MailEnable Enterprise Edition 1.0 1 MailEnable MailEnable Enterprise Edition 1.0 |
| Not Vulnerable: | |
Discussion
MailEnable IMAP SELECT Request Buffer Overflow Vulnerability
MailEnable's IMAP server is prone to a remotely exploitable stack-based buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to a fixed size memory buffer.
Remote attackers may exploit this vulnerability to execute arbitrary machine code in the context of the affected application. This allows attackers to gain System level privileges, resulting in the complete compromise of the targeted computer.
MailEnable's IMAP server is prone to a remotely exploitable stack-based buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to a fixed size memory buffer.
Remote attackers may exploit this vulnerability to execute arbitrary machine code in the context of the affected application. This allows attackers to gain System level privileges, resulting in the complete compromise of the targeted computer.
Exploit / POC
MailEnable IMAP SELECT Request Buffer Overflow Vulnerability
Proof of concept code causing a crash in the affected service is available.
An exploit (mailenable_imap.pm) as part of the Metasploit Framework has been released.
Proof of concept code causing a crash in the affected service is available.
An exploit (mailenable_imap.pm) as part of the Metasploit Framework has been released.
Solution / Fix
MailEnable IMAP SELECT Request Buffer Overflow Vulnerability
Solution:
The vendor has provided a hotfix to address this issue:
MailEnable MailEnable Enterprise Edition 1.0 2
MailEnable MailEnable Enterprise Edition 1.0
MailEnable MailEnable Enterprise Edition 1.0 1
MailEnable MailEnable Enterprise Edition 1.0 3
MailEnable MailEnable Enterprise Edition 1.0 4
MailEnable MailEnable Professional 1.5
MailEnable MailEnable Professional 1.51
MailEnable MailEnable Professional 1.52
MailEnable MailEnable Professional 1.53
MailEnable MailEnable Professional 1.54
Solution:
The vendor has provided a hotfix to address this issue:
MailEnable MailEnable Enterprise Edition 1.0 2
-
MailEnable MEIMSM-HF050530.zip
http://www.mailenable.com/hotfix/MEIMSM-HF050530.zip
MailEnable MailEnable Enterprise Edition 1.0
-
MailEnable MEIMSM-HF050530.zip
http://www.mailenable.com/hotfix/MEIMSM-HF050530.zip
MailEnable MailEnable Enterprise Edition 1.0 1
-
MailEnable MEIMSM-HF050530.zip
http://www.mailenable.com/hotfix/MEIMSM-HF050530.zip
MailEnable MailEnable Enterprise Edition 1.0 3
-
MailEnable MEIMSM-HF050530.zip
http://www.mailenable.com/hotfix/MEIMSM-HF050530.zip
MailEnable MailEnable Enterprise Edition 1.0 4
-
MailEnable MEIMSM-HF050530.zip
http://www.mailenable.com/hotfix/MEIMSM-HF050530.zip
MailEnable MailEnable Professional 1.5
-
MailEnable MEIMSM-HF050530.zip
http://www.mailenable.com/hotfix/MEIMSM-HF050530.zip
MailEnable MailEnable Professional 1.51
-
MailEnable MEIMSM-HF050530.zip
http://www.mailenable.com/hotfix/MEIMSM-HF050530.zip
MailEnable MailEnable Professional 1.52
-
MailEnable MEIMSM-HF050530.zip
http://www.mailenable.com/hotfix/MEIMSM-HF050530.zip
MailEnable MailEnable Professional 1.53
-
MailEnable MEIMSM-HF050530.zip
http://www.mailenable.com/hotfix/MEIMSM-HF050530.zip
MailEnable MailEnable Professional 1.54
-
MailEnable MEIMSM-HF050530.zip
http://www.mailenable.com/hotfix/MEIMSM-HF050530.zip
References
MailEnable IMAP SELECT Request Buffer Overflow Vulnerability
References:
References:
- MailEnable Buffer Overflow Vulnerability (Core Security Technologies)
- MailEnable Homepage (MailEnable)
- MailEnable Hotfix Page (MailEnable)