SmartMax MailMax Popmax Buffer Overflow Vulnerability
BID:5285
Info
SmartMax MailMax Popmax Buffer Overflow Vulnerability
| Bugtraq ID: | 5285 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2002 12:00AM |
| Updated: | Jul 23 2002 12:00AM |
| Credit: | Discovery of this issue is credited to 2c79cbe14ac7d0b8472d3f129fa1df <[email protected]>. |
| Vulnerable: |
SmartMax Software MailMax 4.8 |
| Not Vulnerable: | |
Discussion
SmartMax MailMax Popmax Buffer Overflow Vulnerability
Reportedly, MailMax is vulnerable to buffer overflow attacks against its POP3 daemon, popmax. The vulnerability occurs due to improper bounds checking of the 'USER' argument.
It is possible for an attacker to cause the buffer overflow condition in popmax by submitting an overly large value for the 'USER' argument. This will cause popmax to crash and execute attacker supplied code.
Reportedly, MailMax is vulnerable to buffer overflow attacks against its POP3 daemon, popmax. The vulnerability occurs due to improper bounds checking of the 'USER' argument.
It is possible for an attacker to cause the buffer overflow condition in popmax by submitting an overly large value for the 'USER' argument. This will cause popmax to crash and execute attacker supplied code.
Exploit / POC
SmartMax MailMax Popmax Buffer Overflow Vulnerability
The following exploit and patch were submitted by 2c79cbe14ac7d0b8472d3f129fa1df <[email protected]>.
** It should be noted that the patch was not tested for functionality nor verified to be free of backdoors by SecurityFocus.
The following exploit and patch were submitted by 2c79cbe14ac7d0b8472d3f129fa1df <[email protected]>.
** It should be noted that the patch was not tested for functionality nor verified to be free of backdoors by SecurityFocus.
Solution / Fix
SmartMax MailMax Popmax Buffer Overflow Vulnerability
Solution:
SmartMax Software has made a corrected version of PopMax Server 4.8 available:
SmartMax Software MailMax 4.8
Solution:
SmartMax Software has made a corrected version of PopMax Server 4.8 available:
SmartMax Software MailMax 4.8
-
SmartMax Software popmax.exe
ftp://ftp.smartmax.com/pub/Upgrades/MailMax4/popmax.exe
References
SmartMax MailMax Popmax Buffer Overflow Vulnerability
References:
References:
- MailMax Homepage (SmartMax Software)