MDaemon Email Server Multiple Buffer Overflow Vulnerabilities
BID:29494
Info
MDaemon Email Server Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 29494 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2008 12:00AM |
| Updated: | Jun 02 2008 12:00AM |
| Credit: | securfrog |
| Vulnerable: |
Altn MDaemon Email Server 9.6.5 |
| Not Vulnerable: | |
Discussion
MDaemon Email Server Multiple Buffer Overflow Vulnerabilities
MDaemon Email Server is prone to multiple buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied input before copying it to insufficiently sized buffers.
Successfully exploiting these issues will allow an attacker to execute arbitrary code on the server in the context of the application. Failed exploit attempts will likely crash the application.
These issues affect MDaemon Email Server 9.6.5 and prior versions.
MDaemon Email Server is prone to multiple buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied input before copying it to insufficiently sized buffers.
Successfully exploiting these issues will allow an attacker to execute arbitrary code on the server in the context of the application. Failed exploit attempts will likely crash the application.
These issues affect MDaemon Email Server 9.6.5 and prior versions.
Exploit / POC
MDaemon Email Server Multiple Buffer Overflow Vulnerabilities
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
MDaemon Email Server Multiple Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MDaemon Email Server Multiple Buffer Overflow Vulnerabilities
References:
References:
- Alt-N Homepage (Alt-N)
- MDaemon Product Homepage (Alt-N)
- WorldClient Product Homepage (Alt-N)