Rover POP3 Server is vulnerable to a DoS attack (long USER)
27 Dec. 1999
Summary
Rover POP3 Server V1.1 for NT by aVirt, is a full-featured Internet/Intranet server software package that includes: POP3, and SMTP (Ports 25 and 110). This package contains a vulnerability that allows remote attackers to perform a Denial of Service attack against the product, effectively causing the server to stop responding.
Vulnerable systems:
Rover POP3 Server V1.1 NT and earlier
UssrLabs found a Local / Remote Buffer overflow, the buffer overflow is caused by supplying a long user name, 10000 characters, and the reconnection to the server.