20040922 Remote buffer overflow in MDaemon IMAP and SMTP servermailing list
http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026770.html CVE-2004-1546
Alt-N MDaemon 6.5.1 SMTP Server - Multiple Command Remote Overflows
Record summary
CVE-2004-1546 has a selected CVSS score of 5.0; EIP currently links 2 catalogued exploits.
Description
Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or MAIL command to the SMTP server or (2) LIST command to the IMAP server.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBAlt-N MDaemon 6.5.1 SMTP Server - Multiple Command Remote OverflowsExploitDB exploitby D_BuGNot analyzed1 file
ExploitDBAlt-N MDaemon 6.5.1 - IMAP/SMTP Remote Buffer OverflowExploitDB exploitby D_BuGNot analyzed1 file
References
920040922 Remote buffer overflow in MDaemon IMAP and SMTP servermailing list
http://marc.info/?l=bugtraq&m=109591179510781&w=2 10223vdb entry
http://www.osvdb.org/10223 10224vdb entry
http://www.osvdb.org/10224 11238vdb entry
http://www.securityfocus.com/bid/11238 securitylab.ru
http://www.securitylab.ru/48146.html mdaemon-imap-list-bo(17476)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17476 mdaemon-smtp-bo(17477)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17477 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1546