IMail POP3 Buffer Overflow Denial of Service Vulnerability
BID:789
Info
IMail POP3 Buffer Overflow Denial of Service Vulnerability
| Bugtraq ID: | 789 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Nov 08 1999 12:00AM |
| Updated: | Nov 08 1999 12:00AM |
| Credit: | This vulnerability was posted to Bugtraq by Shok <[email protected]>. |
| Vulnerable: |
Ipswitch IMail 5.0.7 Ipswitch IMail 5.0.6 Ipswitch IMail 5.0.5 |
| Not Vulnerable: | |
Discussion
IMail POP3 Buffer Overflow Denial of Service Vulnerability
There is a buffer overflow in the username field when the username is between 200 and 500 characters. Although it may be possible to execute arbitrary code on the vulnerable server, current exploits only cause a denial of service on the remote machine.
There is a buffer overflow in the username field when the username is between 200 and 500 characters. Although it may be possible to execute arbitrary code on the vulnerable server, current exploits only cause a denial of service on the remote machine.
Exploit / POC
IMail POP3 Buffer Overflow Denial of Service Vulnerability
Exploit available:
Exploit available:
Solution / Fix
IMail POP3 Buffer Overflow Denial of Service Vulnerability
Solution:
Ipswitch has posted a patch on their site. It is available at:
ftp://ftp.ipswitch.com/Ipswitch/Product_Support/IMail/imail508.exe
Solution:
Ipswitch has posted a patch on their site. It is available at:
ftp://ftp.ipswitch.com/Ipswitch/Product_Support/IMail/imail508.exe
References
IMail POP3 Buffer Overflow Denial of Service Vulnerability
References:
References: