Microsoft Exchange Server AUTH / XAUTH / AUTHINFO DoS Vulnerabilities
BID:924
Info
Microsoft Exchange Server AUTH / XAUTH / AUTHINFO DoS Vulnerabilities
| Bugtraq ID: | 924 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 24 1998 12:00AM |
| Updated: | Jul 24 1998 12:00AM |
| Credit: | Discovered by Jon Larimer of ISS X-Force <[email protected]>. Published in an ISS advisory on July 24, 1998. |
| Vulnerable: |
Microsoft Exchange Server 5.5 Microsoft Exchange Server 5.0 SP2 Microsoft Exchange Server 5.0 SP1 Microsoft Exchange Server 5.0 |
| Not Vulnerable: |
Microsoft Exchange Server 5.5 SP3 Microsoft Exchange Server 5.5 SP2 Microsoft Exchange Server 5.5 SP1 |
Discussion
Microsoft Exchange Server AUTH / XAUTH / AUTHINFO DoS Vulnerabilities
Due to overflowable buffers in Exchange Server, it is possible for an attacker to remotely cause the Internet Mail Service or Information Store to stop responding.
Internet Mail Service handles SMTP (email) functionality for Exchange Server. If an attacker connects to port 25 and issues a long AUTH or XAUTH command, the service will stop responding. Other Exchange services should continue to function normally, and IMS can be restarted without rebooting the OS to restore full functionality.
The Information Store handles NNTP (newsgroups) functionality for Exchange Server. If an attacker connects to port 119 and issues a long AUTHINFO command, the service will stop responding. Other Exchange services may fail after the Information Store crashes, and all functionality can be restored by restarting the Information Store service without having to reboot the OS.
Due to overflowable buffers in Exchange Server, it is possible for an attacker to remotely cause the Internet Mail Service or Information Store to stop responding.
Internet Mail Service handles SMTP (email) functionality for Exchange Server. If an attacker connects to port 25 and issues a long AUTH or XAUTH command, the service will stop responding. Other Exchange services should continue to function normally, and IMS can be restarted without rebooting the OS to restore full functionality.
The Information Store handles NNTP (newsgroups) functionality for Exchange Server. If an attacker connects to port 119 and issues a long AUTHINFO command, the service will stop responding. Other Exchange services may fail after the Information Store crashes, and all functionality can be restored by restarting the Information Store service without having to reboot the OS.
Exploit / POC
Microsoft Exchange Server AUTH / XAUTH / AUTHINFO DoS Vulnerabilities
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Exchange Server AUTH / XAUTH / AUTHINFO DoS Vulnerabilities
Solution:
Microsoft has released patches to address these issue, available at:
Exchange 5.0 Internet Mail Service SMTP):
ftp://ftp.microsoft.com/bussys/exchange/exchange-public/fixes/Eng/Exchg5.0/Post-SP2-IMS/
Exchange 5.0 Information Store (NNTP):
ftp://ftp.microsoft.com/bussys/exchange/exchange-public/fixes/Eng/Exchg5.0/Post-SP2-STORE/
Exchange 5.5:
These patches are available as part of Service Pack 1 and later, available at:
ftp://ftp.microsoft.com/bussys/exchange/exchange-public/fixes/Eng/Exchg5.5/
Solution:
Microsoft has released patches to address these issue, available at:
Exchange 5.0 Internet Mail Service SMTP):
ftp://ftp.microsoft.com/bussys/exchange/exchange-public/fixes/Eng/Exchg5.0/Post-SP2-IMS/
Exchange 5.0 Information Store (NNTP):
ftp://ftp.microsoft.com/bussys/exchange/exchange-public/fixes/Eng/Exchg5.0/Post-SP2-STORE/
Exchange 5.5:
These patches are available as part of Service Pack 1 and later, available at:
ftp://ftp.microsoft.com/bussys/exchange/exchange-public/fixes/Eng/Exchg5.5/
References
Microsoft Exchange Server AUTH / XAUTH / AUTHINFO DoS Vulnerabilities
References:
References: