IPSwitch IMail SMTP Buffer Overflow Vulnerability
BID:2651
Info
IPSwitch IMail SMTP Buffer Overflow Vulnerability
| Bugtraq ID: | 2651 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2001 12:00AM |
| Updated: | Apr 24 2001 12:00AM |
| Credit: | Reported to bugtraq by eEye Digital Security <[email protected]> on April 25, 2001. |
| Vulnerable: |
Ipswitch IMail 6.0.6 Ipswitch IMail 6.0.5 Ipswitch IMail 6.0.4 Ipswitch IMail 6.0.3 Ipswitch IMail 6.0.2 Ipswitch IMail 6.0.1 Ipswitch IMail 6.0 |
| Not Vulnerable: | |
Discussion
IPSwitch IMail SMTP Buffer Overflow Vulnerability
IMail is a Windows NT/2000-based e-mail server from IPSwitch.
A vulnerability exists in IMail's SMTP daemon.
The IMail SMTP daemon passes certain SMTP requests to a section of code which handles mailing lists. A flaw exists in this code which results in a failure to properly validate user-supplied input.
As a result, a buffer overflow can be triggered by SMTP requests which include the name of a mailing list hosted by the vulnerable server.
If properly-structured hostile code is also included in the request, it will be executed with SYSTEM privileges.
This can allow the remote execution of arbitrary hostile code on the system hosting IMail.
IMail is a Windows NT/2000-based e-mail server from IPSwitch.
A vulnerability exists in IMail's SMTP daemon.
The IMail SMTP daemon passes certain SMTP requests to a section of code which handles mailing lists. A flaw exists in this code which results in a failure to properly validate user-supplied input.
As a result, a buffer overflow can be triggered by SMTP requests which include the name of a mailing list hosted by the vulnerable server.
If properly-structured hostile code is also included in the request, it will be executed with SYSTEM privileges.
This can allow the remote execution of arbitrary hostile code on the system hosting IMail.