MsgCore/NT Denial of Service Vulnerability
BID:930
Info
MsgCore/NT Denial of Service Vulnerability
| Bugtraq ID: | 930 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 13 2000 12:00AM |
| Updated: | Jan 13 2000 12:00AM |
| Credit: | This vulnerability was first published in U.S.S.R Labs advisory USSR-2000031 on January 13, 2000. |
| Vulnerable: |
Nosque Workshop MsgCore 1.9 |
| Not Vulnerable: |
Nosque Workshop MsgCore 2.10 |
Discussion
MsgCore/NT Denial of Service Vulnerability
There is a denial of service condition in Nosque Workshop's MsgCore SMTP server. The problem lies in memory used to store server input not being deallocated and eventually exhausted, causing the target NT host to freeze requiring a reboot. If a smtp client (or user sending input manually) sends multiple sequences of "HELO/ MAIL FROM/ RCPT TO / DATA" in a single connection, the memory allocated to store all of those values will not be freed and the target will stop functioning once memory runs out.
There is a denial of service condition in Nosque Workshop's MsgCore SMTP server. The problem lies in memory used to store server input not being deallocated and eventually exhausted, causing the target NT host to freeze requiring a reboot. If a smtp client (or user sending input manually) sends multiple sequences of "HELO/ MAIL FROM/ RCPT TO / DATA" in a single connection, the memory allocated to store all of those values will not be freed and the target will stop functioning once memory runs out.
Exploit / POC
MsgCore/NT Denial of Service Vulnerability
Exploit available:
Exploit available: