OSVDB ID: 23796

Title: Ipswitch IMail Server/Collaboration Suite IMAP FETCH Command Overflow

Info

Disclosure

Mar 09, 2006

Discovery

Unknown

Dates

Exploit

Mar 13, 2006

Solution

Mar 09, 2006

Description

A remote overflow exists in Ipswitch IMail Server and Collaboration Suite. The product fails to verify the length of a buffer associated with the FETCH command resulting in a buffer overflow. With a specially crafted command, an attacker can cause the server to crash or possibly execute arbitrary code resulting in a loss of availability or integrity.

Classification

Location: Remote / Network Access
Attack Type: Denial of Service, Input Manipulation
Impact: Loss of Integrity, Loss of Availability
Solution: Upgrade
Exploit: Exploit Public, Exploit Private, Exploit Commercial
Disclosure: OSVDB Verified, Vendor Verified

Solution

Upgrade to version 2006.03 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Ipswitch, Inc.

Collaboration Suite

2006.03 Premium Edition
2006.03 Standard Edition

IMail Server

2006.03

IMail Secure Server

2006.03

References

Credit

  • TippingPoint - TippingPoint
  • Manuel Santamarina Suarez -


Direct URL: http://osvdb.org/23796