|
|
Family: Gain root remotely --> Category: infos
MDaemon < 9.0.6 POP3 Server Buffer Overflow Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary Checks version of MDaemon POP3 Server
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote POP3 server is affected by multiple buffer overflow flaws.
Description :
The remote host is running Alt-N MDaemon, a mail server for Windows.
According to its banner, the POP3 server bundled with the version of
MDaemon on the remote host has two buffer overflows that can be
triggered with long arguments to the 'USER' and 'APOP' commands. By
exploiting these issues, a remote, unauthenticated user can reportedly
crash the affected service or run arbitrary code with LOCAL SYSTEM
rights.
See also :
http://www.infigo.hr/en/in_focus/advisories/INFIGO-2006-08-04
http://www.securityfocus.com/archive/1/444015/30/0/threaded
http://files.altn.com/MDaemon/Release/RelNotes_en.txt
Solution :
Upgrade to MDaemon version 9.0.6 or later.
Threat Level:
Low / CVSS Base Score : 2.3
(AV:R/AC:L/Au:NR/C:N/I:N/A:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|