Mercury Mail Remote Mailbox Name Service Buffer Overflow Vulnerability
BID:16396
Info
Mercury Mail Remote Mailbox Name Service Buffer Overflow Vulnerability
| Bugtraq ID: | 16396 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-4411 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2006 12:00AM |
| Updated: | Dec 11 2008 11:41PM |
| Credit: | kcope <[email protected]> discovered this issue. |
| Vulnerable: |
David Harris Mercury (win32 version) 4.0 1b David Harris Mercury (win32 version) 4.0 1a |
| Not Vulnerable: | |
Discussion
Mercury Mail Remote Mailbox Name Service Buffer Overflow Vulnerability
Mercury Mail is prone to a remote buffer-overflow vulnerability in its mailbox name service. This issue occurs because the application fails to properly bounds-check user-supplied input before copying it to a finite-sized memory buffer.
Exploiting this vulnerability allows remote attackers to execute arbitrary machine code with SYSTEM privileges in the context of the affected server process.
Mercury Mail 4.01b is affected; other versions may also be affected.
Mercury Mail is prone to a remote buffer-overflow vulnerability in its mailbox name service. This issue occurs because the application fails to properly bounds-check user-supplied input before copying it to a finite-sized memory buffer.
Exploiting this vulnerability allows remote attackers to execute arbitrary machine code with SYSTEM privileges in the context of the affected server process.
Mercury Mail 4.01b is affected; other versions may also be affected.
Exploit / POC
Mercury Mail Remote Mailbox Name Service Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
Mercury Mail Remote Mailbox Name Service Buffer Overflow Vulnerability
Solution:
The vendor has released a patch to address this issue.
David Harris Mercury (win32 version) 4.0 1b
David Harris Mercury (win32 version) 4.0 1a
Solution:
The vendor has released a patch to address this issue.
David Harris Mercury (win32 version) 4.0 1b
-
David Harris m4-whfix.zip
ftp://ftp.usm.maine.edu/pegasus/mercury32/m4-whfix.zip
David Harris Mercury (win32 version) 4.0 1a
-
David Harris m4-whfix.zip
ftp://ftp.usm.maine.edu/pegasus/mercury32/m4-whfix.zip
References
Mercury Mail Remote Mailbox Name Service Buffer Overflow Vulnerability
References:
References:
- January 2006 - Security Patches (pmail)
- Mercury MTA Overview (David Harris)