OSVDB ID: 18070

Title: MDaemon IMAP Multiple AUTHENTICATE Commands Remote Overflow

Info

Disclosure

Jul 18, 2005

Discovery

Unknown

Dates

Exploit

Jul 18, 2005

Solution

Unknown

Description

A remote overflow exists in MDaemon IMAP server. MDaemon fails to validate the boundary of the CREATE command. With a specially crafted request, an authorized attacker can cause a buffer overflow, resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public
Disclosure: OSVDB Verified

Solution

Upgrade to version 8.10 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Alt-N Technologies

MDaemon

8.03

References

Credit

  • kcope - kingcopegmx.net -


Direct URL: http://osvdb.org/18070