[30112] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0

daemon@ATHENA.MIT.EDU (millhouse@dsns.net)
Tue May 13 15:45:18 2003

Date: 12 May 2003 23:02:57 -0000
Message-ID: <20030512230257.18171.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: <millhouse@dsns.net>
To: bugtraq@securityfocus.com

In-Reply-To: <000a01c316d1$a7b15ae0$1601a8c0@pc1441>

Hi, i found a buffer overflow in CMailServer 4.0 a few weeks ago that 
already had been discovered in CMailServer 3.3 in May 2002. It seems that 
this bug has not been fixed in the current version. The buffer overflow is 
in the USER command makes it possible to overwrite the EIP. The problem is 
that every capital letter in the buffer that could given with the overflow 
is converted to small letters, so its impossible for me to write a working 
exploit that executes code.

E:\>telnet localhost 110
+OK CMailServer 4.0 POP3 Service Ready
USER "A"x524



millhouse, www.dsns.net

home help back first fref pref prev next nref lref last post