MailEnable POP Service "PASS" Command Buffer Overflow
19 Dec. 2006
Summary
"MailEnable's mail server software provides a powerful, scalable hosted messaging platform for Microsoft Windows. MailEnable offers stability, unsurpassed flexibility and an extensive feature set which allows you to provide cost-effective mail services". Secunia Research has discovered a vulnerability in MailEnable, which can be exploited by malicious people to compromise a vulnerable system.
Vulnerable Systems:
* MailEnable Enterprise Edition version 2.35
* MailEnable Professional Edition version 2.35
The vulnerability is caused due to a boundary error in the POP service when handling arguments passed to the "PASS" command. This can be exploited to cause a stack-based buffer overflow by passing an overly long, specially crafted string as argument to the affected command.
Successful exploitation allows execution of arbitrary code.