|
Brought to you by:
Suppliers of:
|
|
|
| |
Novell NetMail is an e-mail and calendar system that is based on standard Internet protocols.
Exploitation allows authenticated remote attackers to execute arbitrary code with the privileges of the underlying user. |
| |
Credit:
The information has been provided by iDefense.
The original article can be found at:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=455
|
| |
Vulnerable Systems:
* Novell NetMail version 3.52d.
* earlier versions suspected.
Immune Systems:
* Novell NetMail version 3.52e FTF2.
Remote exploitation of a buffer overflow vulnerability in Novell Inc.'s NetMail IMAP daemon allows authenticated attackers to execute arbitrary code with the privileges of the underlying user.
Once logged in, attackers can execute the "subscribe" command with an overly long argument string to overflow a stack based buffer.
Vendor Status:
Novell has addressed this vulnerability in version 3.52e FTF2 of NetMail.
For more information consult Novell TID 3717068.
Disclosure Timeline:
* 10/10/2006 - Initial vendor notification
* 10/11/2006 - Initial vendor response
* 12/23/2006 - Coordinated public disclosure
|
|
|
|
|