[16612] in bugtraq

home help back first fref pref prev next nref lref last post

[NEWS] XMail vulnerable to a remotely exploitable buffer overflow

daemon@ATHENA.MIT.EDU (Aviram Jenik)
Wed Sep 6 19:31:31 2000

Mime-Version: 1.0
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: 7bit
Message-Id:  <070601c01847$01ea4990$0201a8c0@aviram>
Date:         Wed, 6 Sep 2000 23:11:21 +0200
Reply-To: Aviram Jenik <aviram@BEYONDSECURITY.COM>
From: Aviram Jenik <aviram@BEYONDSECURITY.COM>
To: BUGTRAQ@SECURITYFOCUS.COM

The following security advisory is sent to the securiteam mailing list, and
can be found at the SecuriTeam web site: http://www.securiteam.com


XMail vulnerable to a remotely exploitable buffer overflow (APOP, USER)
----------------------------------------------------------------------------
----


SUMMARY

 <http://www.maticad.it/davide/xmail.asp> XMail is an Internet and
Intranet mail server featuring an SMTP server, POP3 server, finger server,
multiple domains, and more. XMail's parsing function does not perform
proper bound checking when parsing the APOP and USER commands, and this
allows a remote attacker to execute arbitrary code by issuing a long APOP
or USER commands.

DETAILS

Vulnerable systems:
XMail version prior to 0.59

Immune systems:
XMail version 0.59

By issuing standard POP3 commands to the XMail POP3 server it is possible
to cause it to overflow an internal buffer, thus causing it to execute
arbitrary code.

For example, after you connect to an XMail POP server, sending any of the
commands:
USER [a buffer of over 256 characters]
APOP [a buffer of over 256 characters] [a buffer of over 256 characters]

will crash the server. If the buffer is properly crafted, arbitrary code
can be executed.

Patch:
A patched version can be downloaded from:
http://www.maticad.it/davide/xmail.asp


ADDITIONAL INFORMATION

The security hole was discovered by Beyond Security's SecuriTeam
(expert@securiteam.com).



====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any
kind.
In no event shall we be liable for any damages whatsoever including direct,
indirect, incidental, consequential, loss of business profits or special
damages.
====================







--
Aviram Jenik
Beyond Security Ltd.
http://www.BeyondSecurity.com
http://www.SecuriTeam.com

home help back first fref pref prev next nref lref last post