Alt-N MDaemon IMAP DoS Vulnerability
BID:2508
Info
Alt-N MDaemon IMAP DoS Vulnerability
| Bugtraq ID: | 2508 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0584 CVE-2001-0584 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 23 2001 12:00AM |
| Updated: | Mar 19 2015 08:18AM |
| Credit: | Discovered and posted to Bugtraq by <[email protected]> on March 25, 2001. |
| Vulnerable: |
Alt-N MDaemon 6.7.9 Alt-N MDaemon 6.7.5 Alt-N MDaemon 6.5 .0 Alt-N MDaemon 6.0.7 Alt-N MDaemon 6.0.6 Alt-N MDaemon 6.0.5 Alt-N MDaemon 6.0 .0 Alt-N MDaemon 5.0.7 Alt-N MDaemon 3.5.6 |
| Not Vulnerable: |
Alt-N MDaemon 6.8 .0 |
Discussion
Alt-N MDaemon IMAP DoS Vulnerability
A successfully logged-in user, via IMAP, could cause MDaemon to terminate the connection. If the user submits either a 'SELECT' or 'EXAMINE' command appended with 250 or more characters, MDaemon will refuse any new connections to the IMAP service. A restart of the service is required in order to gain normal functionality.
A successfully logged-in user, via IMAP, could cause MDaemon to terminate the connection. If the user submits either a 'SELECT' or 'EXAMINE' command appended with 250 or more characters, MDaemon will refuse any new connections to the IMAP service. A restart of the service is required in order to gain normal functionality.
Exploit / POC
Alt-N MDaemon IMAP DoS Vulnerability
The following example has been provided by <[email protected]>:
* OK company.mail IMAP4rev1 MDaemon 3.5.6 ready
1 LOGIN JOE PASSWORD
* OK LOGIN completed
1 SELECT AAAAAAA....
The following example has been provided by <[email protected]>:
* OK company.mail IMAP4rev1 MDaemon 3.5.6 ready
1 LOGIN JOE PASSWORD
* OK LOGIN completed
1 SELECT AAAAAAA....
Solution / Fix
Alt-N MDaemon IMAP DoS Vulnerability
Solution:
It has been reported that this issue is resolved in version 6.8.0 of the software. This information has not been confirmed by the vendor.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that this issue is resolved in version 6.8.0 of the software. This information has not been confirmed by the vendor.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Alt-N MDaemon IMAP DoS Vulnerability
References:
References: