MailServer by SH39 Denial of Service Vulnerability
BID:4232
Info
MailServer by SH39 Denial of Service Vulnerability
| Bugtraq ID: | 4232 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-0416 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Reported by Rense Buijen <[email protected]>. |
| Vulnerable: |
SH39 MailServer 1.2.1 |
| Not Vulnerable: |
SH39 MailServer 1.2.2 |
Discussion
MailServer by SH39 Denial of Service Vulnerability
MailServer by SH39 is an SMTP/POP3 server for Microsoft Windows environments.
Reportedly, connecting to port 25 on a MailServer host, and submitting an unusual amount of arbitrary data could initiate a denial of service condition.
This issue may be the result of an unchecked buffer. If this is the case, there is a possibility that arbitrary code may be executed on the vulnerable target. However, this has not yet been confirmed.
MailServer by SH39 is an SMTP/POP3 server for Microsoft Windows environments.
Reportedly, connecting to port 25 on a MailServer host, and submitting an unusual amount of arbitrary data could initiate a denial of service condition.
This issue may be the result of an unchecked buffer. If this is the case, there is a possibility that arbitrary code may be executed on the vulnerable target. However, this has not yet been confirmed.
Exploit / POC
MailServer by SH39 Denial of Service Vulnerability
No exploit code required.
No exploit code required.
Solution / Fix
MailServer by SH39 Denial of Service Vulnerability
Solution:
Reportedly, MailServer version 1.2.2 addresses this issue:
SH39 MailServer 1.2.1
Solution:
Reportedly, MailServer version 1.2.2 addresses this issue:
SH39 MailServer 1.2.1
-
SH39 MailServer
http://sh39.net/ms/MailServer.zip