SmartMax MailMax Password Field Buffer Overflow Denial Of Service Vulnerability
BID:7326
Info
SmartMax MailMax Password Field Buffer Overflow Denial Of Service Vulnerability
| Bugtraq ID: | 7326 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2003 12:00AM |
| Updated: | Apr 11 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Dennis Rand" <[email protected]>. |
| Vulnerable: |
SmartMax Software MailMax 5.0.10 .7 SmartMax Software MailMax 5.0.10 .6 SmartMax Software MailMax 5.0 |
| Not Vulnerable: |
SmartMax Software MailMax 5.5 SmartMax Software MailMax 5.0.10 .8 |
Discussion
SmartMax MailMax Password Field Buffer Overflow Denial Of Service Vulnerability
A buffer overflow vulnerability has been reported for MailMax that may result in a a denial of service condition. The vulnerability exists when users attempt to login to the IMAP server using an overly long password. This will cause the service to crash.
A buffer overflow vulnerability has been reported for MailMax that may result in a a denial of service condition. The vulnerability exists when users attempt to login to the IMAP server using an overly long password. This will cause the service to crash.
Exploit / POC
SmartMax MailMax Password Field Buffer Overflow Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SmartMax MailMax Password Field Buffer Overflow Denial Of Service Vulnerability
Solution:
The vendor has stated that MailMax 5.5 will be released in the near future containing fixes for this vulnerability. Until then, affected users are advised to update existing files.
The vendor has provided replacement files:
SmartMax Software MailMax 5.0
SmartMax Software MailMax 5.0.10 .6
SmartMax Software MailMax 5.0.10 .7
Solution:
The vendor has stated that MailMax 5.5 will be released in the near future containing fixes for this vulnerability. Until then, affected users are advised to update existing files.
The vendor has provided replacement files:
SmartMax Software MailMax 5.0
-
SmartMax Software MailMax 5 Files
ftp://ftp.smartmax.com/updates/MailMax 5.0/
SmartMax Software MailMax 5.0.10 .6
-
SmartMax Software MailMax 5 Files
ftp://ftp.smartmax.com/updates/MailMax 5.0/
SmartMax Software MailMax 5.0.10 .7
-
SmartMax Software MailMax 5 Files
ftp://ftp.smartmax.com/updates/MailMax 5.0/
References
SmartMax MailMax Password Field Buffer Overflow Denial Of Service Vulnerability
References:
References:
- MailMax Homepage (SmartMax Software)
- Buffer Overflow Vulnerability Found in MailMax Version 5 ("Dennis Rand"
)