|
|
| |
| MDaemon suffers from a Denial-of-Service vulnerability due to its handling of buffers within the IMAP and webconfig services. The result is that a malicious user can bring down several services (including SMTP and POP3). |
| |
Credit:
The information has been provided by Peter Gr?ndl of Decom labs.
|
| |
Vulnerable systems:
MDaemon version 3.5.0
Immune systems:
MDaemon version 3.5.1.0
Sending a long string (e.g. 30K) followed by \r\n to port 143 would cause the MDaemon service to crash and would additionally bring down the services on ports 25, 110, 366 (default installation).
An old flaw has been reintroduced into MDaemon (originally discovered by USSR Labs: Multiple DoS attack vulnerabilities in MDaemon Server). The webconfig service (port 3001) is vulnerable to a long URL attack. The size is 242-4077 chars. Registers are overwritten at following offsets (242-249 results in missing values being overwritten with hex 00): EDI: (250:249:248:247) & ECX: (254.253.252.251)
Solution:
Upgrade to MDaemon 3.5.1.0:
http://mdaemon.deerfield.com/download/getmdaemon.cfm
|
|
|
|
|