aVirt Rover POP3 Server Buffer Overflow DoS Vulnerability
BID:894
Info
aVirt Rover POP3 Server Buffer Overflow DoS Vulnerability
| Bugtraq ID: | 894 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 27 1999 12:00AM |
| Updated: | Dec 27 1999 12:00AM |
| Credit: | Posted to Bugtraq on December 27, 1999 by USSR Labs. |
| Vulnerable: |
Avirt Rover 1.1 for NT |
| Not Vulnerable: | |
Discussion
aVirt Rover POP3 Server Buffer Overflow DoS Vulnerability
The Rover POP3 mailserver from aVirt is vulnerable to a remote DoS attack due to an unchecked buffer in the code that reads in the username. If a username of more than 10000 characters is specified, the server will crash the next time someone connects.
The Rover POP3 mailserver from aVirt is vulnerable to a remote DoS attack due to an unchecked buffer in the code that reads in the username. If a username of more than 10000 characters is specified, the server will crash the next time someone connects.
Exploit / POC
aVirt Rover POP3 Server Buffer Overflow DoS Vulnerability
An exploit for this vulnerability is available at http://www.ussrback.com
An exploit for this vulnerability is available at http://www.ussrback.com
Solution / Fix
aVirt Rover POP3 Server Buffer Overflow DoS Vulnerability
Solution:
Rover is no longer supported by aVirt. Available upgrades are Avirt Mail 3.5 or Avirt Mail v4 RC1.
Solution:
Rover is no longer supported by aVirt. Available upgrades are Avirt Mail 3.5 or Avirt Mail v4 RC1.
References
aVirt Rover POP3 Server Buffer Overflow DoS Vulnerability
References:
References: