Microsoft CIS IMAP Buffer Overflow Vulnerability
BID:912
Info
Microsoft CIS IMAP Buffer Overflow Vulnerability
| Bugtraq ID: | 912 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 04 2000 12:00AM |
| Updated: | Jan 04 2000 12:00AM |
| Credit: | Discovered by Tristan Goode and publicized by Microsoft in Microsoft Security Bulletin MS00-001 on January 4, 1999. |
| Vulnerable: |
Microsoft Commercial Internet System 2.5 Microsoft Commercial Internet System 2.0 |
| Not Vulnerable: | |
Discussion
Microsoft CIS IMAP Buffer Overflow Vulnerability
Microsoft's Commercial Internet System has an unchecked buffer in the IMAP service that could allow an attacker to crash or execute arbitrary code on the server.
Only MCIS servers that are running mail services with IMAP enabled are vulnerable to this attack.
Microsoft's Commercial Internet System has an unchecked buffer in the IMAP service that could allow an attacker to crash or execute arbitrary code on the server.
Only MCIS servers that are running mail services with IMAP enabled are vulnerable to this attack.
Exploit / POC
Microsoft CIS IMAP Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft CIS IMAP Buffer Overflow Vulnerability
Solution:
Microsoft has released a patch for this issue, available at:
Intel:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=17124
Alpha:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=17122
Solution:
Microsoft has released a patch for this issue, available at:
Intel:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=17124
Alpha:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=17122