Thanks for that confident and reassuring reply Daniel!
-V

----- Original Message -----
From: Daniel Donnelly <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, June 18, 1999 10:50 AM
Subject: Re: [IMail Forum] Does IPSwitch have an Answer for this? - Security
Alert


> Old news! If one looks in his Release Notes and has V5.03 or later, you
would
> see that these have been addressed. You can also find Release notes in our
> KnowledgeBase.
>
> Daniel Donnelly
> Ipswitch Technical Support
> ________________________________________________________
> See our Knowledge Base at http://support.ipswitch.com/kb
> URL for List Servers: http://www.ipswitch.com/Support/mailing-lists.html
>
>
> In reply to 17 Jun message from [EMAIL PROTECTED]:
>
> >Multiple IMail Vulnerabilites
>
> >Systems Affected
> >IMail 5.0
>
> >Release Date
> >March 1, 1999
>
> >Advisory Code
> >AD03011999
>
> >Description:
>
> >The following holes can be used as a Denial of Service against the
> >various services mentioned and in some cases used to remotely execute
> >code.
>
> >Imapd (143)
>
> >The imapd login process does not do proper bounds checking on usernames
> >and passwords.
>
> >* OK IMAP4 Server (IMail 4.06)
> >X LOGIN glob1 glob2
>
> >Where glob1 is 1200 characters and glob2 is 1300 characters. The imapd
> >service will crash with the usuall overflow error.
>
> >LDAP (389)
>
> >Telnet to server.com 389
> >Send: Y glob1
> >hit enter twice
> >Server Returns: 0
> >Send: Y glob2
> >hit enter
>
> >Where glob1 and glob2 are 2375 characters and Y is Y. The ldap service
> >goes to 90 percent or so and idles there. Therefore using up most
> system
> >resources.
>
> >IMonitor (8181)
>
> >Telnet to server.com 8181
> >Send: glob1
> >hit enter twice
>
> >Where glob1 is 2045 characters. The IMonitor service crashes with the
> >normal overflow message.
>
> >IMail Web Service (8383)
>
> >Telnet to server.com 8383
> >Send: GET /glob1/
>
> >Where glob1 is 3000 characters. The usual overflow message will be
> >displayed. This one looks to be easily exploitable. >:-]
>
> >Whois32 Daemon (43)
>
> >Telnet to server.com 43
> >Send glob1
>
> >Where glob1 is 1000 characters. The usual overflow message will be
> >displayed. Ya... starting to sound old.
>
> >Vendor Status
>
> >Vendor has been notified, Waiting for response...
>
> >Copyright (c) 1999 eEye Digital Security Team
> >Permission is hereby granted for the redistribution of this alert
> >electronically. It is not to be edited in any way without express
> >consent of eEye. If you wish to reprint the whole or any part of this
> >alert in any other medium excluding electronic medium, please e-mail
> >[EMAIL PROTECTED] for permission.
>
> >Disclaimer:
>
> >The information within this paper may change without notice. Use of
> this
> >information constitutes acceptance for use in an AS IS condition. There
> >are NO warranties with regard to this information. In no event shall
> the
> >author be liable for any damages whatsoever arising out of or in
> >connection with the use or spread of this information. Any use of this
> >information is at the user's own risk.
>
> >Please send suggestions, updates, and comments to:
>
> >eEye Digital Security Team
>
> >[EMAIL PROTECTED]
> >http://www.eEye.com
>
> >-Mark McDonald
> >[EMAIL PROTECTED]
>
> >Voice: 800.610.9856, Ext. 231 - Fax: 888.333.2710
>
>
>
>

Reply via email to