T. Hauck Jana Server POP3 Gateway Server Response Buffer Overflow Vulnerability
BID:5322
Info
T. Hauck Jana Server POP3 Gateway Server Response Buffer Overflow Vulnerability
| Bugtraq ID: | 5322 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1061 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 26 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Discovered by 3APA3A <[email protected]>. |
| Vulnerable: |
T. Hauck Jana Webserver 2.2.1 T. Hauck Jana Webserver 2.0 Beta2 T. Hauck Jana Webserver 2.0 Beta1 T. Hauck Jana Webserver 2.0 T. Hauck Jana Webserver 1.46 T. Hauck Jana Webserver 1.45 T. Hauck Jana Webserver 1.0 |
| Not Vulnerable: | |
Discussion
T. Hauck Jana Server POP3 Gateway Server Response Buffer Overflow Vulnerability
Jana Server is a server for Microsoft Windows based systems. Jana Server provides a wide range of proxy servers, and a number of other services. A POP3 gateway service is provided.
A buffer overflow vulnerability has been reported in the POP3 gateway service. A malicious server may return an oversized reply to Jana Server. This may result in the corruption of process memory, and the vulnerable server crashing.
It has been reported possible to exploit this condition by returning an oversized argument to the '+OK' response.
Jana Server is a server for Microsoft Windows based systems. Jana Server provides a wide range of proxy servers, and a number of other services. A POP3 gateway service is provided.
A buffer overflow vulnerability has been reported in the POP3 gateway service. A malicious server may return an oversized reply to Jana Server. This may result in the corruption of process memory, and the vulnerable server crashing.
It has been reported possible to exploit this condition by returning an oversized argument to the '+OK' response.
Exploit / POC
T. Hauck Jana Server POP3 Gateway Server Response Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
T. Hauck Jana Server POP3 Gateway Server Response Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
T. Hauck Jana Server POP3 Gateway Server Response Buffer Overflow Vulnerability
References:
References:
- Jana Webserver (Thomas Hauck)