Ipswitch IMail Web Service Buffer Overflow DoS Vulnerability
BID:505
Info
Ipswitch IMail Web Service Buffer Overflow DoS Vulnerability
| Bugtraq ID: | 505 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-1551 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 01 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | eEye Advisory AD03011999 posted to Bugtraq March 1, 1999 by MArc of eEye <[email protected]>. |
| Vulnerable: |
Ipswitch IMail 6.0 Ipswitch IMail 5.0 |
| Not Vulnerable: | |
Discussion
Ipswitch IMail Web Service Buffer Overflow DoS Vulnerability
The IMail web server can be crashed by requesting an abnormally long URL.
The IMail web server can be crashed by requesting an abnormally long URL.
Exploit / POC
Ipswitch IMail Web Service Buffer Overflow DoS Vulnerability
Telnet to target machine, port 8383
Send: GET /glob1/
Where glob1 is 3000 characters.
Marc Maiffret <[email protected]> has released the following exploit:
Telnet to target machine, port 8383
Send: GET /glob1/
Where glob1 is 3000 characters.
Marc Maiffret <[email protected]> has released the following exploit:
Solution / Fix
Ipswitch IMail Web Service Buffer Overflow DoS Vulnerability
Solution:
Ipswitch have released patches which eliminates the vulnerability. They can be downloaded at the following location:
http://www.ipswitch.com/support/patches-upgrades.html#IMail
Solution:
Ipswitch have released patches which eliminates the vulnerability. They can be downloaded at the following location:
http://www.ipswitch.com/support/patches-upgrades.html#IMail
References
Ipswitch IMail Web Service Buffer Overflow DoS Vulnerability
References:
References: