Internet Anywhere Mail Server DoS Vulnerability
BID:733
Info
Internet Anywhere Mail Server DoS Vulnerability
| Bugtraq ID: | 733 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-1999-1500 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 01 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | Discovered and posted to NTBugtraq by Arne Vidstrom on Oct 1, 1999 |
| Vulnerable: |
True North Software Internet Anywhere Mail Server 2.3 |
| Not Vulnerable: |
True North Software Internet Anywhere Mail Server 3.1 |
Discussion
Internet Anywhere Mail Server DoS Vulnerability
The POP3 commands "list", "top", and "uidl", if sent with arguments that are letters instead of the expected numbers, will crash the server.
The POP3 commands "list", "top", and "uidl", if sent with arguments that are letters instead of the expected numbers, will crash the server.
Exploit / POC
Internet Anywhere Mail Server DoS Vulnerability
See discussion
See discussion
Solution / Fix
Internet Anywhere Mail Server DoS Vulnerability
Solution:
This issue has been fixed in the latest release of IAMS, 3.1 . This software is available from True North Software's web page, at:
http://www.tnsoft.com/mailserver
Solution:
This issue has been fixed in the latest release of IAMS, 3.1 . This software is available from True North Software's web page, at:
http://www.tnsoft.com/mailserver
References
Internet Anywhere Mail Server DoS Vulnerability
References:
References:
- Internet Anywhere(TM) Mail Server - Welcome (True North Software)