Ipswitch IMail Web Calender Buffer Overflow Vulnerability
BID:3431
Info
Ipswitch IMail Web Calender Buffer Overflow Vulnerability
| Bugtraq ID: | 3431 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-1287 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered and posted to Bugtraq in a Defcom Labs Advisory def-2001-29 on Oct 12, 2001. |
| Vulnerable: |
Ipswitch IMail 7.0.4 |
| Not Vulnerable: | |
Discussion
Ipswitch IMail Web Calender Buffer Overflow Vulnerability
Ipswitch IMail is an email server that serves clients their mail via a web interface. IMail supports most common email protocols such as SMTP, POP3, IMAP4, and LDAP etc.
Due to improper bounds checking, the Web Calendaring feature of IMail could allow the execution of arbitrary code with the privileges of SYSTEM. This is achieveable by submitting a specially crafted GET request.
Ipswitch IMail is an email server that serves clients their mail via a web interface. IMail supports most common email protocols such as SMTP, POP3, IMAP4, and LDAP etc.
Due to improper bounds checking, the Web Calendaring feature of IMail could allow the execution of arbitrary code with the privileges of SYSTEM. This is achieveable by submitting a specially crafted GET request.
Exploit / POC
Ipswitch IMail Web Calender Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Ipswitch IMail Web Calender Buffer Overflow Vulnerability
References:
References:
- IMail Server Homepage (Ipswitch)