MERCUR Mailserver Control-Service Buffer Overflow Vulnerability
BID:5261
Info
MERCUR Mailserver Control-Service Buffer Overflow Vulnerability
| Bugtraq ID: | 5261 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1073 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Discovery of this issue is credited to 2c79cbe14ac7d0b8472d3f129fa1df <[email protected]>. |
| Vulnerable: |
Atrium Software MERCUR Mailserver 4.2 Atrium Software MERCUR Mailserver 4.0 1 SP1 Atrium Software MERCUR Mailserver 4.0 1 Atrium Software MERCUR Mailserver 3.3 SP2 Atrium Software MERCUR Mailserver 3.3 SP1 Atrium Software MERCUR Mailserver 3.3 |
| Not Vulnerable: | |
Discussion
MERCUR Mailserver Control-Service Buffer Overflow Vulnerability
MERCUR Mailserver is prone to a remotely exploitable buffer overflow condition. The condition is due to insufficient bounds checking in the Control-Service component, which listens on TCP port 32000 by default. It is possible to corrupt process memory by supplying an overly long username/password. Attackers may exploit this condition to execute arbitrary instructions with the privileges of the mailserver.
MERCUR Mailserver is prone to a remotely exploitable buffer overflow condition. The condition is due to insufficient bounds checking in the Control-Service component, which listens on TCP port 32000 by default. It is possible to corrupt process memory by supplying an overly long username/password. Attackers may exploit this condition to execute arbitrary instructions with the privileges of the mailserver.
Solution / Fix
MERCUR Mailserver Control-Service Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.