ArGoSoft Mail Server Pro POP3 Server Remote Information Disclosure Vulnerability
BID:16808
Info
ArGoSoft Mail Server Pro POP3 Server Remote Information Disclosure Vulnerability
| Bugtraq ID: | 16808 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2006 12:00AM |
| Updated: | Feb 27 2006 04:26PM |
| Credit: | Discovery of this issue is credited to the NSA Group. |
| Vulnerable: |
ArGoSoft Mail Server Pro 1.8.8 .1 |
| Not Vulnerable: | |
Discussion
ArGoSoft Mail Server Pro POP3 Server Remote Information Disclosure Vulnerability
The ArGoSoft Mail Server Pro POP3 service is susceptible to a remote information-disclosure vulnerability. This issue is due to the application's failure to require authentication before allowing a command that discloses potentially sensitive information.
This issue allows remote, unauthenticated attackers to gain access to potentially sensitive configuration information. Information that the attacker harvests in this manner may then aid in further attacks.
Version 1.8.8.1 is vulnerable to this issue; other versions may also be affected.
The ArGoSoft Mail Server Pro POP3 service is susceptible to a remote information-disclosure vulnerability. This issue is due to the application's failure to require authentication before allowing a command that discloses potentially sensitive information.
This issue allows remote, unauthenticated attackers to gain access to potentially sensitive configuration information. Information that the attacker harvests in this manner may then aid in further attacks.
Version 1.8.8.1 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
ArGoSoft Mail Server Pro POP3 Server Remote Information Disclosure Vulnerability
An attacker likely exploits this issue with 'telnet', or other such network tools.
An attacker likely exploits this issue with 'telnet', or other such network tools.
Solution / Fix
ArGoSoft Mail Server Pro POP3 Server Remote Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ArGoSoft Mail Server Pro POP3 Server Remote Information Disclosure Vulnerability
References:
References:
- ArGoSoft Mail Server Pro 1.8 POP3 (NSA Group)
- Mail Server Homepage (ArGoSoft)