MDaemon IMAP AUTHENTICATE command buffer overflow
Added: 03/01/2006BID: 14317
OSVDB: 18069
![]() |
|
![]() |
|
MDaemon IMAP AUTHENTICATE command buffer overflowAdded: 03/01/2006BID: 14317 OSVDB: 18069 BackgroundMDaemon is an e-mail server for Windows.ProblemThe IMAP service in MDaemon is affected by buffer overflow vulnerabilities in the AUTHENTICATE LOGIN and AUTHENTICATE CRAM-MD5 commands which can be exploited without logging into the server.ResolutionUpgrade to MDaemon 8.0.4 or higher.Referenceshttp://archives.neohapsis.com/archives/fulldisclosure/2005-07/0442.htmlLimitationsExploit works on MDaemon 8.0.3.PlatformsWindows |