Novell Netmail IMAP 'AUTHENTICATE GSSAPI' Buffer Overflow Vulnerability
BID:27567
Info
Novell Netmail IMAP 'AUTHENTICATE GSSAPI' Buffer Overflow Vulnerability
| Bugtraq ID: | 27567 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2006 12:00AM |
| Updated: | Feb 04 2008 02:56PM |
| Credit: | An anonymous researcher discovered this issue. |
| Vulnerable: |
Novell NetMail 3.52 D Novell NetMail 3.52 C1 Novell NetMail 3.52 C Novell NetMail 3.52 B Novell NetMail 3.52 A Novell NetMail 3.52 |
| Not Vulnerable: | |
Discussion
Novell Netmail IMAP 'AUTHENTICATE GSSAPI' Buffer Overflow Vulnerability
Novell Netmail is prone to a stack-based buffer-overflow vulnerability because it fails to perform sufficient bounds checking on user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker could leverage this issue to execute arbitrary code with administrative privileges. A successful exploit could result in the complete compromise of affected computers.
Novell Netmail is prone to a stack-based buffer-overflow vulnerability because it fails to perform sufficient bounds checking on user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker could leverage this issue to execute arbitrary code with administrative privileges. A successful exploit could result in the complete compromise of affected computers.
Exploit / POC
Novell Netmail IMAP 'AUTHENTICATE GSSAPI' Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available as a module for the Metasploit Framework:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available as a module for the Metasploit Framework:
Solution / Fix
Novell Netmail IMAP 'AUTHENTICATE GSSAPI' Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Novell Netmail IMAP 'AUTHENTICATE GSSAPI' Buffer Overflow Vulnerability
References:
References:
- NetMail Product Page (Novell)