MailEnable SMTP NTLM Authentication Multiple Vulnerabilities
BID:20290
Info
MailEnable SMTP NTLM Authentication Multiple Vulnerabilities
| Bugtraq ID: | 20290 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-5177 CVE-2006-5176 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2006 12:00AM |
| Updated: | Feb 14 2007 11:47PM |
| Credit: | Discovered by Mu Security research team. |
| Vulnerable: |
MailEnable MailEnable Professional 2.351 MailEnable MailEnable Professional 2.35 MailEnable MailEnable Professional 2.34 MailEnable MailEnable Professional 2.33 MailEnable MailEnable Professional 2.32 MailEnable MailEnable Professional 2.0 MailEnable MailEnable Enterprise Edition 2.35 MailEnable MailEnable Enterprise Edition 2.34 MailEnable MailEnable Enterprise Edition 2.33 MailEnable MailEnable Enterprise Edition 2.32 MailEnable MailEnable Enterprise Edition 2.0 |
| Not Vulnerable: | |
Discussion
MailEnable SMTP NTLM Authentication Multiple Vulnerabilities
MailEnable is prone to multiple remote vulnerabilities.
These issues arise in the SMTP server during NTLM authentication and may facilitate arbitrary code execution or denial-of-service conditions.
MailEnable Professional 2.0 and MailEnable Enterprise 2.0 are reported vulnerable to these issues.
MailEnable is prone to multiple remote vulnerabilities.
These issues arise in the SMTP server during NTLM authentication and may facilitate arbitrary code execution or denial-of-service conditions.
MailEnable Professional 2.0 and MailEnable Enterprise 2.0 are reported vulnerable to these issues.
Exploit / POC
MailEnable SMTP NTLM Authentication Multiple Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
The following proof of concept is available to trigger denial-of-service conditions:
Removed maildisable-v7-20290.pl PoC; this is a separate issue discussed in BID 22565 (MailEnable SMTP NTLM Authentication Buffer Overflow Vulnerability)
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
The following proof of concept is available to trigger denial-of-service conditions:
Removed maildisable-v7-20290.pl PoC; this is a separate issue discussed in BID 22565 (MailEnable SMTP NTLM Authentication Buffer Overflow Vulnerability)
Solution / Fix
MailEnable SMTP NTLM Authentication Multiple Vulnerabilities
Solution:
The vendor has released an update to address these issues.
MailEnable MailEnable Enterprise Edition 2.0
MailEnable MailEnable Professional 2.0
Solution:
The vendor has released an update to address these issues.
MailEnable MailEnable Enterprise Edition 2.0
-
MailEnable MESMTP-060930.zip
http://www.mailenable.com/hotfix/MESMTP-060930.zip
MailEnable MailEnable Professional 2.0
-
MailEnable MESMTP-060930.zip
http://www.mailenable.com/hotfix/MESMTP-060930.zip
References
MailEnable SMTP NTLM Authentication Multiple Vulnerabilities
References:
References:
- MailEnable Homepage (MailEnable)
- MailEnable Hotfix Page (MailEnable)
- Multiple Pre-Authentication Vulnerabilities in MailEnable SMTP [MU-200609-01] (Mu Security)