IMail IMAP service contains a buffer overflow

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: IMailIMAPOverflow

Platforms: Imail
Description:

IMail is a popular multi-protocol mail server for Windows NT environments. A buffer overflow in the login command of the IMAP server could allow a remote attacker to crash the service. It is not known whether this overflow can be manipulated to gain access to the machine.

Remedy:

This vulnerability has been demonstrated through version 5.0, and later versions may be vulnerable as well. Users are encouraged to contact IPSwitch for fix information.

References:

Ipswitch, Inc. Product Information, IMail Server by Ipswitch, http://www.ipswitch.com/Products/IMail_Server/index.asp

eEye Digital Security Team Alert AD03011999, Multiple IMail Vulnerabilities Multiple IMail Vulnerabilites, http://www.eeye.com/database/advisories/ad03011999/ad03011999.html


X-Force Logo
Know Your Risks