Multiple DoS attack vulnerabilities in MDaemon Server
3 Jan. 2000
Summary
UssrLabs recently found multiple places in the MDaemon Server where buffer bounds aren't checked correctly. This results in a possible Denial of Service attack against the service in question.
Credit:
The information has been provided by: Ussr Labs.
By connecting to MDaemon's services (WorldClient - port 2000) or WebConfig (port 2002) a remote attacker can cause the MDaemon Server to crash - effectively causing a Denial of Service attack.
These two remote services can be subjected to a buffer overflow when sending a large URL.