Microsoft Exchange Server IMC EHLO Response Buffer Overflow Vulnerability
BID:5306
Info
Microsoft Exchange Server IMC EHLO Response Buffer Overflow Vulnerability
| Bugtraq ID: | 5306 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2002 12:00AM |
| Updated: | Jul 25 2002 12:00AM |
| Credit: | Discovered by ISS X-Force. |
| Vulnerable: |
Microsoft Exchange Server 5.5 SP4 Microsoft Exchange Server 5.5 SP3 Microsoft Exchange Server 5.5 SP2 Microsoft Exchange Server 5.5 SP1 Microsoft Exchange Server 5.5 |
| Not Vulnerable: | |
Discussion
Microsoft Exchange Server IMC EHLO Response Buffer Overflow Vulnerability
Microsoft Exchange Server includes a component called Internet Mail Connector (IMC) that allows an Exchange server to communicate with remote SMTP servers. A vulnerability exists in this component that may allow for remote attackers to execute arbitrary code on Exchange servers under specific circumstances.
The exploitable condition occurs when the affected server is generating a response to a Extended Hello (EHLO) SMTP command received from a remote server. An unbounded string creation routine (likely sprintf()) is used to construct the response string in memory. As externally supplied data is included in the construction of this string, the unbounded string creation may be exploited to overwrite stack memory and execute arbitrary code.
The external data included in the string is obtained through a reverse lookup. To exploit this vulnerability, an attacker would require authority over his address space and map a PTR hostname of excessive length to the attacking IP address. Furthermore, a replacement return address and possibly shellcode would also be embedded. These specific circumstances complicate exploitability and make real-world attacks unlikely. Theoretically, the vulnerability is exploitable and administrators are advised to apply the patch as soon as possible.
Microsoft Exchange Server includes a component called Internet Mail Connector (IMC) that allows an Exchange server to communicate with remote SMTP servers. A vulnerability exists in this component that may allow for remote attackers to execute arbitrary code on Exchange servers under specific circumstances.
The exploitable condition occurs when the affected server is generating a response to a Extended Hello (EHLO) SMTP command received from a remote server. An unbounded string creation routine (likely sprintf()) is used to construct the response string in memory. As externally supplied data is included in the construction of this string, the unbounded string creation may be exploited to overwrite stack memory and execute arbitrary code.
The external data included in the string is obtained through a reverse lookup. To exploit this vulnerability, an attacker would require authority over his address space and map a PTR hostname of excessive length to the attacking IP address. Furthermore, a replacement return address and possibly shellcode would also be embedded. These specific circumstances complicate exploitability and make real-world attacks unlikely. Theoretically, the vulnerability is exploitable and administrators are advised to apply the patch as soon as possible.
Exploit / POC
Microsoft Exchange Server IMC EHLO Response Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Exchange Server IMC EHLO Response Buffer Overflow Vulnerability
Solution:
Microsoft has released a patch:
Microsoft Exchange Server 5.5 SP4
Solution:
Microsoft has released a patch:
Microsoft Exchange Server 5.5 SP4
-
Microsoft Q326322
For Exchange Server 5.5 SP4 running on Microsoft Windows NT4 / 2000.
http://download.microsoft.com/download/exch55/Patch/05.05.59.2656/NT45 /EN-US/Q326322enui386.EXE
References
Microsoft Exchange Server IMC EHLO Response Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledgebase Article Q190026 (Microsoft)
- Microsoft Security Bulletin MS02-037 (Microsoft)
- Technet Security (Microsoft)