Alt-N MDaemon/WorldClient Form2Raw Raw Message Handler Buffer Overflow Vulnerability
BID:9317
Info
Alt-N MDaemon/WorldClient Form2Raw Raw Message Handler Buffer Overflow Vulnerability
| Bugtraq ID: | 9317 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-1200 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2003 12:00AM |
| Updated: | Mar 19 2015 08:37AM |
| Credit: | The disclosure of this issue has been credited to Pejamn Davarzani <[email protected]> and Behrang Fouladi<[email protected]>. |
| Vulnerable: |
Altn MDaemon 6.8.5 Altn MDaemon 6.8.4 Altn MDaemon 6.8.3 Altn MDaemon 6.8.2 Altn MDaemon 6.8.1 Altn MDaemon 6.8 .0 Altn MDaemon 6.7.9 Altn MDaemon 6.7.5 Altn MDaemon 6.5.2 |
| Not Vulnerable: | |
Discussion
Alt-N MDaemon/WorldClient Form2Raw Raw Message Handler Buffer Overflow Vulnerability
It has been reported that MDaemon/WorldClient mail server may be prone to a buffer overflow vulnerability when handling certain messages with a 'From' field of over 249 bytes. This issue may allow a remote attacker to gain unauthorized access to a system.
Successful exploitation of this issue may allow an attacker to execute arbitrary code in the context of the vulnerable software in order to gain unauthorized access.
It has been reported that MDaemon/WorldClient mail server may be prone to a buffer overflow vulnerability when handling certain messages with a 'From' field of over 249 bytes. This issue may allow a remote attacker to gain unauthorized access to a system.
Successful exploitation of this issue may allow an attacker to execute arbitrary code in the context of the vulnerable software in order to gain unauthorized access.
Exploit / POC
Alt-N MDaemon/WorldClient Form2Raw Raw Message Handler Buffer Overflow Vulnerability
Proof of concept exploit has been provided. Exploit code has been provided by rave <[email protected]>.
CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.
Proof of concept exploit has been provided. Exploit code has been provided by rave <[email protected]>.
CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.
Solution / Fix
Alt-N MDaemon/WorldClient Form2Raw Raw Message Handler Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Alt-N MDaemon/WorldClient Form2Raw Raw Message Handler Buffer Overflow Vulnerability
References:
References:
- MDaemon Form2Raw exploit (CORE Security)
- [Hat-Squad] Remote buffer overflow in Mdaemon Raw message Handler (Hat-Squad Security Team
) - Rosiello Security's exploit for MDaemon (Angelo Rosiello
)