Old news! If one looks in his Release Notes and has V5.03 or later, you would
see that these have been addressed. You can also find Release notes in our
KnowledgeBase.

Daniel Donnelly
Ipswitch Technical Support
________________________________________________________
See our Knowledge Base at http://support.ipswitch.com/kb
URL for List Servers: http://www.ipswitch.com/Support/mailing-lists.html


In reply to 17 Jun message from [EMAIL PROTECTED]:

>Multiple IMail Vulnerabilites

>Systems Affected
>IMail 5.0

>Release Date
>March 1, 1999

>Advisory Code
>AD03011999

>Description:

>The following holes can be used as a Denial of Service against the
>various services mentioned and in some cases used to remotely execute
>code. 

>Imapd (143)

>The imapd login process does not do proper bounds checking on usernames
>and passwords.

>* OK IMAP4 Server (IMail 4.06)
>X LOGIN glob1 glob2

>Where glob1 is 1200 characters and glob2 is 1300 characters. The imapd 
>service will crash with the usuall overflow error. 

>LDAP (389)

>Telnet to server.com 389
>Send: Y glob1 
>hit enter twice
>Server Returns: 0
>Send: Y glob2
>hit enter

>Where glob1 and glob2 are 2375 characters and Y is Y. The ldap service
>goes to 90 percent or so and idles there. Therefore using up most
system
>resources.

>IMonitor (8181)

>Telnet to server.com 8181
>Send: glob1
>hit enter twice

>Where glob1 is 2045 characters. The IMonitor service crashes with the
>normal overflow message.

>IMail Web Service (8383)

>Telnet to server.com 8383
>Send: GET /glob1/

>Where glob1 is 3000 characters. The usual overflow message will be 
>displayed. This one looks to be easily exploitable. >:-] 

>Whois32 Daemon (43)

>Telnet to server.com 43
>Send glob1

>Where glob1 is 1000 characters. The usual overflow message will be 
>displayed. Ya... starting to sound old.

>Vendor Status

>Vendor has been notified, Waiting for response...

>Copyright (c) 1999 eEye Digital Security Team
>Permission is hereby granted for the redistribution of this alert 
>electronically. It is not to be edited in any way without express
>consent of eEye. If you wish to reprint the whole or any part of this
>alert in any other medium excluding electronic medium, please e-mail
>[EMAIL PROTECTED] for permission.

>Disclaimer:

>The information within this paper may change without notice. Use of
this
>information constitutes acceptance for use in an AS IS condition. There
>are NO warranties with regard to this information. In no event shall
the
>author be liable for any damages whatsoever arising out of or in
>connection with the use or spread of this information. Any use of this
>information is at the user's own risk.

>Please send suggestions, updates, and comments to: 

>eEye Digital Security Team

>[EMAIL PROTECTED]
>http://www.eEye.com

>-Mark McDonald
>[EMAIL PROTECTED]

>Voice: 800.610.9856, Ext. 231 - Fax: 888.333.2710


Reply via email to