Alt-N MDaemon IMAP Server Authentication Routines Remote Buffer Overflow Vulnerability
BID:14317
Info
Alt-N MDaemon IMAP Server Authentication Routines Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 14317 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2005 12:00AM |
| Updated: | Jul 19 2005 12:00AM |
| Credit: | Discovery is credited to kcope <[email protected]>. |
| Vulnerable: |
Alt-N MDaemon 8.0 3 Alt-N MDaemon 8.0 2 Alt-N MDaemon 8.0 1 Alt-N MDaemon 8.0 |
| Not Vulnerable: | |
Discussion
Alt-N MDaemon IMAP Server Authentication Routines Remote Buffer Overflow Vulnerability
Alt-N MDaemon IMAP Server is affected by a remote buffer overflow vulnerability.
A specially crafted request can corrupt process memory and lead to an overflow condition.
This issue may be leveraged to execute arbitrary code in the context of the server. This may facilitate unauthorized access to the affected computer.
Alt-N MDaemon 8.03 is reported to be vulnerable. Other versions are likely affected as well.
Alt-N MDaemon IMAP Server is affected by a remote buffer overflow vulnerability.
A specially crafted request can corrupt process memory and lead to an overflow condition.
This issue may be leveraged to execute arbitrary code in the context of the server. This may facilitate unauthorized access to the affected computer.
Alt-N MDaemon 8.03 is reported to be vulnerable. Other versions are likely affected as well.
Exploit / POC
Alt-N MDaemon IMAP Server Authentication Routines Remote Buffer Overflow Vulnerability
A proof of concept is available.
The mdaemon_imap.pm exploit is available.
The mdaemon_imap_cram_md5.pm exploit is available for Metasploit.
A proof of concept is available.
The mdaemon_imap.pm exploit is available.
The mdaemon_imap_cram_md5.pm exploit is available for Metasploit.
Solution / Fix
Alt-N MDaemon IMAP Server Authentication Routines Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Alt-N MDaemon IMAP Server Authentication Routines Remote Buffer Overflow Vulnerability
References:
References:
- Alt-N Homepage (Alt-N)