Alt-N MDaemon Multiple Remote Pre-Authentication POP3 Buffer Overflow Vulnerabilities
BID:19651
CVE-2006-4364 |Info
Alt-N MDaemon Multiple Remote Pre-Authentication POP3 Buffer Overflow Vulnerabilities
| Bugtraq ID: | 19651 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 21 2006 12:00AM |
| Updated: | Aug 26 2006 11:19PM |
| Credit: | Discovery is credited to Leon Juranic. |
| Vulnerable: |
Alt-N MDaemon 8.1.3 Alt-N MDaemon 8.1.1 Alt-N MDaemon 8.1 Alt-N MDaemon 8.0.5 Alt-N MDaemon 8.0.4 Alt-N MDaemon 8.0 3 Alt-N MDaemon 8.0 2 Alt-N MDaemon 8.0 1 Alt-N MDaemon 8.0 Alt-N MDaemon 7.2 Alt-N MDaemon 6.8.5 Alt-N MDaemon 6.8.4 Alt-N MDaemon 6.8.3 Alt-N MDaemon 6.8.2 Alt-N MDaemon 6.8.1 Alt-N MDaemon 6.8 .0 Alt-N MDaemon 6.7.9 Alt-N MDaemon 6.7.5 Alt-N MDaemon 6.5.2 Alt-N MDaemon 6.5.1 Alt-N MDaemon 6.5 .0 Alt-N MDaemon 6.0.7 Alt-N MDaemon 6.0.6 Alt-N MDaemon 6.0.5 Alt-N MDaemon 6.0 .0 Alt-N MDaemon 5.0.7 Alt-N MDaemon 3.5.6 Alt-N MDaemon 3.5.4 Alt-N MDaemon 3.5.1 Alt-N MDaemon 3.5 .0 Alt-N MDaemon 3.1.2 Alt-N MDaemon 3.1.1 Alt-N MDaemon 3.1 beta Alt-N MDaemon 3.0.4 Alt-N MDaemon 3.0.3 Alt-N MDaemon 2.71 SP1 Alt-N MDaemon 2.8.5 0 Alt-N MDaemon 2.8 Alt-N MDaemon 9.0 |
| Not Vulnerable: |
Alt-N MDaemon 9.0.6 |
Discussion
Alt-N MDaemon Multiple Remote Pre-Authentication POP3 Buffer Overflow Vulnerabilities
Alt-N MDaemon POP3 Server is susceptible to multiple remote buffer-overflow vulnerabilities. The issues are due to the application's failure to properly bounds-check user-supplied input before copying it to insufficiently sized memory buffers.
These issues allow remote, unauthenticated attackers to execute arbitrary machine code in the context of affected servers. This may facilitate the compromise of affected computers.
MDaemon versions 8 and 9 are reported to be vulnerable; previous versions may be affected as well.
Alt-N MDaemon POP3 Server is susceptible to multiple remote buffer-overflow vulnerabilities. The issues are due to the application's failure to properly bounds-check user-supplied input before copying it to insufficiently sized memory buffers.
These issues allow remote, unauthenticated attackers to execute arbitrary machine code in the context of affected servers. This may facilitate the compromise of affected computers.
MDaemon versions 8 and 9 are reported to be vulnerable; previous versions may be affected as well.
Exploit / POC
Alt-N MDaemon Multiple Remote Pre-Authentication POP3 Buffer Overflow Vulnerabilities
The following proof-of-concept exploit code demonstrates these vulnerabilities:
A denial-of-service exploit in python has also been provided.
The following proof-of-concept exploit code demonstrates these vulnerabilities:
A denial-of-service exploit in python has also been provided.
Solution / Fix
Alt-N MDaemon Multiple Remote Pre-Authentication POP3 Buffer Overflow Vulnerabilities
Solution:
The vendor has released an update that addresses these vulnerabilities. Please see the third party and vendor reference for additional information.
Solution:
The vendor has released an update that addresses these vulnerabilities. Please see the third party and vendor reference for additional information.
References
Alt-N MDaemon Multiple Remote Pre-Authentication POP3 Buffer Overflow Vulnerabilities
References:
References:
- INFIGO IS Security Advisory #INFIGO-2006-08-04 (INFIGO Information Security)