OSVDB ID: 6027

Title: MERCUR SMTP Server EXPN Command Remote Overflow

Info

Disclosure

Feb 23, 2001

Discovery

Unknown

Dates

Exploit

Feb 23, 2001

Solution

Unknown

Description

A remote overflow exists in MERCUR SMTP Server. By sending a EXPN command containing a overly long string of random characters, an attacker can cause arbitrary code execution with LocalSystem privileges resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

Atrium Software

MERCUR Messaging Server

3.30.03

References

Credit

  • Martin Rakhmanoff - martindirect.spb.ru -


Direct URL: http://osvdb.org/6027