Mdaemon WebConfig Overflow DoS Vulnerability
BID:820
Info
Mdaemon WebConfig Overflow DoS Vulnerability
| Bugtraq ID: | 820 |
| Class: | Unknown |
| CVE: |
CVE-1999-0844 CVE-1999-0844 |
| Remote: | No |
| Local: | No |
| Published: | Nov 24 1999 12:00AM |
| Updated: | Mar 19 2015 09:48AM |
| Credit: | Posted to Bugtraq on November 24, 1999 by Ussr Labs <[email protected]>. |
| Vulnerable: |
Alt-N MDaemon 2.8.5 0 |
| Not Vulnerable: | |
Discussion
Mdaemon WebConfig Overflow DoS Vulnerability
The Mdaemon mail server for Windows includes a small web server for web-based remote administration. This webserver is vulnerable due to an unchecked buffer that handles incoming GET requests. An abnormally large URL sent to the WebConfig service at port 2002 will crash the service.
The Mdaemon mail server for Windows includes a small web server for web-based remote administration. This webserver is vulnerable due to an unchecked buffer that handles incoming GET requests. An abnormally large URL sent to the WebConfig service at port 2002 will crash the service.
Exploit / POC
Mdaemon WebConfig Overflow DoS Vulnerability
Exploit available
Exploit available
Solution / Fix
Mdaemon WebConfig Overflow DoS Vulnerability
Solution:
Alt-N has released a patch for this issue, available at:
http://www.mdaemon.com/helpdesk/hotfix.htm
Solution:
Alt-N has released a patch for this issue, available at:
http://www.mdaemon.com/helpdesk/hotfix.htm
References
Mdaemon WebConfig Overflow DoS Vulnerability
References:
References: