Ipswitch IMail Server LDAP Buffer Overflow Vulnerability
BID:4780
Info
Ipswitch IMail Server LDAP Buffer Overflow Vulnerability
| Bugtraq ID: | 4780 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2002 12:00AM |
| Updated: | May 20 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Foundstone Labs <[email protected]>. |
| Vulnerable: |
Ipswitch IMail 7.1 Ipswitch IMail 7.0.7 Ipswitch IMail 7.0.6 Ipswitch IMail 7.0.5 Ipswitch IMail 7.0.4 Ipswitch IMail 7.0.3 Ipswitch IMail 7.0.2 Ipswitch IMail 7.0.1 Ipswitch IMail 6.4 Ipswitch IMail 6.3 Ipswitch IMail 6.2 Ipswitch IMail 6.1 Ipswitch IMail 6.0.6 Ipswitch IMail 6.0.5 Ipswitch IMail 6.0.4 Ipswitch IMail 6.0.3 Ipswitch IMail 6.0.2 Ipswitch IMail 6.0.1 Ipswitch IMail 6.0 Ipswitch IMail 5.0.8 Ipswitch IMail 5.0.7 Ipswitch IMail 5.0.6 Ipswitch IMail 5.0.5 Ipswitch IMail 5.0 |
| Not Vulnerable: | |
Discussion
Ipswitch IMail Server LDAP Buffer Overflow Vulnerability
Ipswitch IMail is an e-mail server that serves clients their mail via a web interface. It runs on Microsoft Windows operating systems.
The IMail LDAP component is prone to a remotely exploitable buffer overflow condition, allowing attackers to execute arbitrary attacker-supplied instructions.
IMail normally runs in the SYSTEM context, meaning that successful exploitation will result in a full compromise of the underlying system.
It should be noted that this condition may also be exploited to trigger a denial of service.
Ipswitch IMail is an e-mail server that serves clients their mail via a web interface. It runs on Microsoft Windows operating systems.
The IMail LDAP component is prone to a remotely exploitable buffer overflow condition, allowing attackers to execute arbitrary attacker-supplied instructions.
IMail normally runs in the SYSTEM context, meaning that successful exploitation will result in a full compromise of the underlying system.
It should be noted that this condition may also be exploited to trigger a denial of service.
Exploit / POC
Ipswitch IMail Server LDAP Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Ipswitch IMail Server LDAP Buffer Overflow Vulnerability
Solution:
The vendor has released a hotfix which addresses this issue. Users must be running Ipswitch IMail 7.1 to apply the hotfix.
Ipswitch IMail 7.1
Solution:
The vendor has released a hotfix which addresses this issue. Users must be running Ipswitch IMail 7.1 to apply the hotfix.
Ipswitch IMail 7.1
-
Ipswitch IM710HF1.exe
ftp://ftp.ipswitch.com/Ipswitch/Product_Support/IMail/IM710HF1.exe
References
Ipswitch IMail Server LDAP Buffer Overflow Vulnerability
References:
References:
- IMail Home Page (Ipswitch)
- IMail Patches & Upgrades (Ipswitch)