Title: Mercury Mail Transport System IMAP Server Multiple Command Remote Overflow
Info
Disclosure
Nov 29, 2004
Discovery
Unknown
Dates
Exploit
Dec 01, 2004
Solution
Unknown
Description
A buffer overflow exists in Mercury Mail. The IMAP server fails to validate input passed to the EXAMINE, SUBSCRIBE, STATUS, APPEND, CHECK, CLOSE, EXPUNGE, FETCH, RENAME, DELETE, LIST, SEARCH, CREATE, and UNSUBSCRIBE commands resulting in a stack overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.