SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

MDaemon POP3 server remote buffer overflow (preauth)


Arrow  SecurityAlert : 1446
Arrow  CVE : CVE-2006-4364
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : Yes
Arrow  Credit : Sasa Jusic
Arrow  Published : 28.08.2006

Arrow  Affected Software : MDaemon POP3 server



Arrow  Advisory Content :  

INFIGO IS Security Advisory #ADV-2006-08-04
http://www.infigo.hr/

Title: MDaemon POP3 server remote buffer overflow (preauth)
Advisory ID: INFIGO-2006-08-04
Date: 2006-08-21
Advisory URL:
http://www.infigo.hr/en/in_focus/advisories/INFIGO-2006-08-04
Impact: Remote code execution (preauth)
Risk Level: High
Vulnerability Type: Remote
Vendors Status: Vendor contacted on 4th May 2006

==[ Overview

MDaemon Server is a standards-based SMTP/POP/IMAP mail server that offers
a
full range of mail server functionality. MDaemon is designed to manage the
email needs of any number of individual users and comes complete with a
powerful set of integrated tools for managing mail accounts and message
formats. MDaemon offers a scalable SMTP, POP3, and IMAP4 mail server
complete with LDAP support, an integrated browser-based email client,
content filtering, spam filters, extensive security features, and more.
MDaemon can be found on http://www.altn.com/.

==[ Vulnerability

During an audit, a critical vulnerability has been discovered in the
MDaemon POP3 server. There is a buffer overflow vulnerability in 'USER'
and 'APOP' command processing part of the Altn MDaemon POP3 server.
The vulnerability can be triggered with providing a long string to USER or
APOP commands with '@' characters included in the string. In this case,
MDaemon will incorectly process the string and a heap overflow will happen
as a result. To trigger the vulnerability, a few USER commands have to be
sent to the POP3 Server. Sometimes (depending on the heap state and
string length), it is even possible to redirect code execution directly to
the supplied input buffer on the heap.

==[ Affected Version

The vulnerability has been identified in the latest MDaemon 8/9. All
previous versions are believed to be vulnerable as well.

==[ Fix

Vulnerability is fixed in MDaemon 9.06

==[ PoC Exploit

MDaemon POP3 server remote buffer overflow (preauth) PoC can be
downloaded from http://www.infigo.hr/files/mdaemon_poc.pl .

==[ Credits

Vulnerability discovered by Sasa Jusic <sasa.jusic (at) infigo (dot) hr
[email concealed]> and
Leon Juranic <leon.juranic (at) infigo (dot) hr [email concealed]>

==[ INFIGO IS Security Contact

INFIGO IS,

WWW : http://www.infigo.hr
E-mail : infocus (at) infigo (dot) hr [email concealed]





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.