Alt-N WorldClient Long URL DoS Vulnerability

BID:823

Info

Alt-N WorldClient Long URL DoS Vulnerability

Bugtraq ID: 823
Class: Boundary Condition Error
CVE: CVE-1999-0844
CVE-1999-0844
Remote: Yes
Local: Yes
Published: Nov 26 1999 12:00AM
Updated: Mar 19 2015 09:14AM
Credit: Posted to bugtraq on November 25, 1999 by Ussr Labs <[email protected]>.
Vulnerable: Alt-N WorldClient Standard 2.0 .0.0
- Alt-N MDaemon 2.8.5 0
Alt-N WorldClient Pro 2.0.1 .0
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Alt-N WorldClient Pro 2.0 .0.0
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Not Vulnerable:

Discussion

Alt-N WorldClient Long URL DoS Vulnerability

Alt-N's WorldClient is an email webserver that allows it's users to retrieve email via HTTP. It is susceptible to denial of service attacks due to an unchecked buffer in the request handler. Supplying a long url will crash the server.

Exploit / POC

Alt-N WorldClient Long URL DoS Vulnerability

Example:
http ://target.host:2000/[long string]

Solution / Fix

Alt-N WorldClient Long URL DoS Vulnerability

Solution:
Alt-N has released a patch for both Pro and Standard versions of WorldClient. WorldClient Standard only ships as part of Mdaemon, and the patch listed for Standard is in fact an Mdaemon patch which also fixes Bugtraq ID 820, "Mdaemon WebConfig Overflow DoS Vulnerability"

Pro-
http://worldclient.deerfield.com/helpdesk/hotfix.cfm
Standard-
http://www.mdaemon.com/helpdesk/hotfix.htm

References

Alt-N WorldClient Long URL DoS Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report