Ipswitch IMail Server Mailbox Denial of Service Vulnerability
BID:3427
Info
Ipswitch IMail Server Mailbox Denial of Service Vulnerability
| Bugtraq ID: | 3427 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-1283 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered and posted to Bugtraq by Niels Heinen <[email protected]> on Oct 12, 2001. |
| Vulnerable: |
Ipswitch IMail 7.0.4 |
| Not Vulnerable: | |
Discussion
Ipswitch IMail Server Mailbox Denial of Service Vulnerability
Ipswitch IMail is an email server that serves clients their mail via a web interface. IMail supports most common email protocols such as SMTP, POP3, IMAP4, and LDAP, etc.
The IPSwitch IMail Server webmail interface is prone to a denial of service. Theweb interface will crash if a mailbox with a name that contains 248+ dots('.') is accessed. If the webmail interface crashes then it must be restarted to regain normal functionality. CGI scripts that access mailboxes may also induce a denial of service in the same manner.
Though it is unconfirmed, this issue may be caused by a buffer overflow. If thisis the case, a possibility does exist that this issue may be exploited to execute arbitrary code on the host.
Ipswitch IMail is an email server that serves clients their mail via a web interface. IMail supports most common email protocols such as SMTP, POP3, IMAP4, and LDAP, etc.
The IPSwitch IMail Server webmail interface is prone to a denial of service. Theweb interface will crash if a mailbox with a name that contains 248+ dots('.') is accessed. If the webmail interface crashes then it must be restarted to regain normal functionality. CGI scripts that access mailboxes may also induce a denial of service in the same manner.
Though it is unconfirmed, this issue may be caused by a buffer overflow. If thisis the case, a possibility does exist that this issue may be exploited to execute arbitrary code on the host.
Exploit / POC
Ipswitch IMail Server Mailbox Denial of Service Vulnerability
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.
Solution / Fix
Ipswitch IMail Server Mailbox Denial of Service Vulnerability
Solution:
The vendor has released a hotfix.
Ipswitch IMail 7.0.4
Solution:
The vendor has released a hotfix.
Ipswitch IMail 7.0.4
-
Ipswitch IMail Server 7.04 Hotfix 1
ftp://ftp.ipswitch.com/Ipswitch/Product_Support/IMail/imail704.exe
References
Ipswitch IMail Server Mailbox Denial of Service Vulnerability
References:
References:
- IMail Server Homepage (Ipswitch)
- IMail Server News & Updates (IPSwitch)