E-Post MailServer Remote Information Disclosure Vulnerability
BID:28951
Info
E-Post MailServer Remote Information Disclosure Vulnerability
| Bugtraq ID: | 28951 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2049 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | Tan Chew Keong |
| Vulnerable: |
E-POST Inc. Mail Server Enterprise 4.10 E-POST Inc. Mail Server 4.10 E-POST Inc. EPSTPOP3S.EXE 4.22 |
| Not Vulnerable: |
E-POST Inc. EPSTPOP3S.EXE 4.23 |
Discussion
E-Post MailServer Remote Information Disclosure Vulnerability
E-Post MailServer is prone to a remote information-disclosure vulnerability.
Exploiting this issue can allow remote attackers to obtain the POP3 password of any known user from the POP3 service without having to log on. For an exploit to succeed, the attacker must know the POP3 account name (email address) of the victim.
The issue affects E-Post Mail Server 4.10 with EPSTPOP3S.EXE 4.22; other versions may also be affected.
E-Post MailServer is prone to a remote information-disclosure vulnerability.
Exploiting this issue can allow remote attackers to obtain the POP3 password of any known user from the POP3 service without having to log on. For an exploit to succeed, the attacker must know the POP3 account name (email address) of the victim.
The issue affects E-Post Mail Server 4.10 with EPSTPOP3S.EXE 4.22; other versions may also be affected.
Exploit / POC
E-Post MailServer Remote Information Disclosure Vulnerability
The researcher has developed a working exploit, but it is not publicly available.
The researcher has developed a working exploit, but it is not publicly available.
Solution / Fix
E-Post MailServer Remote Information Disclosure Vulnerability
Solution:
The vendor has released EPSTPOP3S.EXE 4.23 to address this issue. Please see the references for more information.
Solution:
The vendor has released EPSTPOP3S.EXE 4.23 to address this issue. Please see the references for more information.
References
E-Post MailServer Remote Information Disclosure Vulnerability
References:
References:
- E-Post Mail Server APOP Password Disclosure Vulnerability (Tan Chew Keong)
- Home Page (E-POST)
- E-Post Mail Server Pass Disclosure advisory (E-Post)