Title: Ipswitch IMail Server/Collaboration Suite IMAP FETCH Command Overflow
Info
Disclosure
Mar 09, 2006
Discovery
Unknown
Dates
Exploit
Mar 13, 2006
Solution
Mar 09, 2006
Description
A remote overflow exists in Ipswitch IMail Server and Collaboration Suite. The product fails to verify the length of a buffer associated with the FETCH command resulting in a buffer overflow. With a specially crafted command, an attacker can cause the server to crash or possibly execute arbitrary code resulting in a loss of availability or integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Integrity,
Loss of Availability
Solution:
Upgrade
Exploit:
Exploit Public,
Exploit Private,
Exploit Commercial
Disclosure:
OSVDB Verified,
Vendor Verified
Solution
Upgrade to version 2006.03 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.