OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[SA13348] Mercury Mail Transport System Command Handling Buffer Overflows

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Thu Dec 02 2004 - 06:51:08 CST


TITLE:
Mercury Mail Transport System Command Handling Buffer Overflows

SECUNIA ADVISORY ID:
SA13348

VERIFY ADVISORY:
http://secunia.com/advisories/13348/

CRITICAL:
Moderately critical

IMPACT:
System access

WHERE:
From remote

SOFTWARE:
Mercury Mail Transport System 3.x
http://secunia.com/product/1997/
Mercury Mail Transport System 4.x
http://secunia.com/product/4348/

DESCRIPTION:
Some vulnerabilities have been reported in Mercury Mail Transport
System, which can be exploited by malicious users to compromise a
vulnerable system.

The vulnerabilities are caused due to boundary errors in the handling
of some commands. This can be exploited to cause a buffer overflow by
supplying an overly long argument (about 512 to 1024 bytes).

The following commands are affected:
* EXAMINE
* SUBSCRIBE
* STATUS
* APPEND
* CHECK
* CLOSE
* EXPUNGE
* FETCH
* RENAME
* DELETE
* LIST
* SEARCH
* CREATE
* UNSUBSCRIBE

The vulnerabilities have been reported in version 4.01a. Other
versions may also be affected.

SOLUTION:
The vulnerabilities will reportedly be fixed in an upcoming version.

PROVIDED AND/OR DISCOVERED BY:
Reed Arvin, NoPh0bia, and JohnH.

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------