Buffer Overflow in Ipswitch's IMail Server
A buffer overflow condition exists in the Lightweight Directory Access Protocol (LDAP) component of Ipswitch's IMail server.
May 21, 2002
Reported May 20, 2002, byFoundstone Labs.
VERSIONS AFFECTED
· Ipswitch’s IMail Server 7.1 andearlier versions
DESCRIPTION
Abuffer overflow condition exists in the Lightweight Directory Access Protocol(LDAP) component of Ipswitch's IMail Server, which can result in a Denial ofService (DoS) attack. An attacker can exploit this vulnerability to remotelyexecute arbitrary code by using the privileges of the IMail daemon, whichtypically has the default of SYSTEM.
VENDOR RESPONSE
Ipswitch hasreleased Hotfix1 for IMail Server 7.10 , which addresses this vulnerability. Users who have earlierversions of IMail Server will need to upgrade to version 7.10.
CREDIT
Discovered by FoundstoneLabs.
About the Author
You May Also Like