Vulnerable Systems:
* Novell NetMail version 3.52d.
Immune Systems:
* NetMail version 3.52e FTF2.
Remote exploitation of a buffer overflow vulnerability in Novell Inc.'s NetMail IMAP daemon allows authenticated attackers to execute arbitrary code with the privileges of the underlying user. Once logged in, attackers can execute the "subscribe" command with an overly long argument string to overflow a stack based buffer.
Vendor Status:
Novell has addressed this vulnerability in version 3.52e FTF2 of NetMail. For more information consult Novell TID 3717068.