IMail LDAP buffer overflow
Added: 07/06/2006CVE: CVE-2004-0297
BID: 9682
OSVDB: 3984
![]() |
|
![]() |
|
IMail LDAP buffer overflowAdded: 07/06/2006CVE: CVE-2004-0297 BID: 9682 OSVDB: 3984 BackgroundIMail is an e-mail server for Windows platforms. It includes a service which implements the Lightweight Directory Access Protocol (LDAP).ProblemA buffer overflow in IMail's LDAP service allows a remote attacker to overwrite the Global Exception Handler by sending long, specially crafted tags, leading to command execution.ResolutionUpgrade to the latest version of IMail or apply IMail 8.05 Hotfix 2.Referenceshttp://www.idefense.com/intelligence/vulnerabilities/display.php?id=74LimitationsExploit works on IMail 8.0.PlatformsWindows |