Floosietek FTGate USER Command Mailbox Lock Vulnerability
BID:4429
Info
Floosietek FTGate USER Command Mailbox Lock Vulnerability
| Bugtraq ID: | 4429 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2002 12:00AM |
| Updated: | Apr 04 2002 12:00AM |
| Credit: | Credited to Ilya Teterin (aka buggzy) and SECURITY.NNOV. |
| Vulnerable: |
Floosietek FTGatePro 1.0 5 Floosietek FTGateOffice 1.0 5 |
| Not Vulnerable: |
Floosietek FTGateLite 1.0 |
Discussion
Floosietek FTGate USER Command Mailbox Lock Vulnerability
Floosietek FTGatePRO and FTGateOffice are high performance, feature rich mail servers for the Microsoft Windows operating system.
The POP3 USER command is used to identify the client user. FTGate locks the mailbox of the given user when this command is received. As this may be done before authentication is complete, it is possible for a malicious attacker to lock the mailbox of another known user through the use of this command.
Floosietek FTGatePRO and FTGateOffice are high performance, feature rich mail servers for the Microsoft Windows operating system.
The POP3 USER command is used to identify the client user. FTGate locks the mailbox of the given user when this command is received. As this may be done before authentication is complete, it is possible for a malicious attacker to lock the mailbox of another known user through the use of this command.