Ipswitch IMail Server Multiple Buffer Overflow Vulnerabilities
BID:24962
Info
Ipswitch IMail Server Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 24962 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-2795 CVE-2007-3925 CVE-2007-3927 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2007 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | Manuel Santamarina Suarez discovered the 'search' vulnerability. An anonymous researcher discovered the 'search charset' vulnerability. The vendor credits TippingPoint and the Zero Day Initiative for reporting the 'Imailsec' and 'subscribe' issues. |
| Vulnerable: |
Ipswitch IMail Server 2006 |
| Not Vulnerable: |
Ipswitch IMail Server 2006.21 |
Discussion
Ipswitch IMail Server Multiple Buffer Overflow Vulnerabilities
Ipswitch IMail Server is prone to multiple buffer-overflow vulnerabilities because the software fails to properly check boundaries on user-supplied data before copying it to an insufficiently sized buffer.
Successful attacks allow arbitrary code to run, facilitating the remote compromise of affected computers. Exploit attempts may also cause the application to crash.
Ipswitch IMail Server 2006 is vulnerable to these issues; other versions may also be affected.
Ipswitch IMail Server is prone to multiple buffer-overflow vulnerabilities because the software fails to properly check boundaries on user-supplied data before copying it to an insufficiently sized buffer.
Successful attacks allow arbitrary code to run, facilitating the remote compromise of affected computers. Exploit attempts may also cause the application to crash.
Ipswitch IMail Server 2006 is vulnerable to these issues; other versions may also be affected.
Exploit / POC
Ipswitch IMail Server Multiple Buffer Overflow Vulnerabilities
The following exploits are available:
The following exploits are available:
Solution / Fix
Ipswitch IMail Server Multiple Buffer Overflow Vulnerabilities
Solution:
The vendor has released fixes to address these issues. Please see the references for more information.
Solution:
The vendor has released fixes to address these issues. Please see the references for more information.
References
Ipswitch IMail Server Multiple Buffer Overflow Vulnerabilities
References:
References:
- IMail Server Homepage (Ipswitch)
- Release notes for IMail Server 2006.21 (v9.21) (Ipswitch)
- ZDI-07-042 Ipswitch IMail Server GetIMailHostEntry Memory Corruption Vulnerabili (Zero Day Initiative)
- ZDI-07-043 - Ipswitch IMail IMAP Daemon SUBSCRIBE Stack Overflow Vulnerability (Zero Day Initiative)
- iDefense Security Advisory 07.18.07: Ipswitch IMail Server 2006 IMAP Search Comm (iDefense Labs
) - ZDI-07-042: Ipswitch IMail Server GetIMailHostEntry Memory Corruption Vulnerabil (ZDI)
- ZDI-07-043: Ipswitch IMail IMAP Daemon SUBSCRIBE Stack Overflow Vulnerability (ZDI)