ArGoSoft Mail Server Pro IMAP Server Remote Directory Traversal Vulnerability
BID:16809
Info
ArGoSoft Mail Server Pro IMAP Server Remote Directory Traversal Vulnerability
| Bugtraq ID: | 16809 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2006 12:00AM |
| Updated: | Feb 27 2006 04:56PM |
| Credit: | Discovery of this issue is credited to the NSA Group. |
| Vulnerable: |
ArGoSoft Mail Server Pro 1.8.8 .1 |
| Not Vulnerable: | |
Discussion
ArGoSoft Mail Server Pro IMAP Server Remote Directory Traversal Vulnerability
The ArGoSoft Mail Server Pro IMAP service is susceptible to a remote directory-traversal vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input.
This issue allows remote, authenticated attackers to create and possibly modify arbitrary files with the privileges of the server process. Since the server process requires elevated privileges to listen on the IMAP TCP port, attackers may likely be able to overwrite or modify any file with SYSTEM-level privileges.
Version 1.8.8.1 is vulnerable to this issue; other versions may also be affected.
The ArGoSoft Mail Server Pro IMAP service is susceptible to a remote directory-traversal vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input.
This issue allows remote, authenticated attackers to create and possibly modify arbitrary files with the privileges of the server process. Since the server process requires elevated privileges to listen on the IMAP TCP port, attackers may likely be able to overwrite or modify any file with SYSTEM-level privileges.
Version 1.8.8.1 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
ArGoSoft Mail Server Pro IMAP Server Remote Directory Traversal Vulnerability
An attacker likely exploits this issue with 'telnet', or other such network tools.
An attacker likely exploits this issue with 'telnet', or other such network tools.
Solution / Fix
ArGoSoft Mail Server Pro IMAP Server Remote Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
ArGoSoft Mail Server Pro IMAP Server Remote Directory Traversal Vulnerability
References:
References:
- ArGoSoft Mail Server Pro 1.8 IMAP (NSA Group)
- Mail Server Homepage (ArGoSoft)
- NSA Group Security Advisory NSAG-?200-24.02.2006 Vulnerability ArGoSoft Mail Ser (NSA Group
)