[NT] Qualcomm WorldMail IMAP Server String Literal Processing Overflow
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 21 Dec 2005 17:06:13 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Qualcomm WorldMail IMAP Server String Literal Processing Overflow
------------------------------------------------------------------------
SUMMARY
<http://www.eudora.com/worldmail/> Qualcomm WorldMail is "an email and
messaging server designed for use in small to large enterprises that
supports IMAP, POP3, SMTP, and web mail features".
Remote exploitation of a buffer overflow vulnerability in Qualcomm
WorldMail IMAP Server allows unauthenticated attackers to execute
arbitrary code.
DETAILS
Vulnerable Systems:
* Qualcomm Worldmail server version 3.0
Successful exploitation of this vulnerability allows attackers to execute
arbitrary code with SYSTEM privileges. This leads to a total compromise of
the mail server.
In order to trigger this overflow, an attacker only needs to send a long
string ending with a '}' character. This will result in a stack overflow
and the attacker may use an SEH overwrite or a standard EBP or EIP
overwrite in order to gain control of the process trivially.
This is a pre-authentication vulnerability. To exploit this vulnerability
an attacker would need to be able connect to the e-mail server and the
IMAP module would have to be enabled (default). Only one command is
required to trigger this vulnerability.
Workaround:
There is no workaround currently available except for disabling IMAP
services.
CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-4267>
CAN-2005-4267
Disclosure Timeline:
* 15.12.05 - Initial vendor notification
* 20.12.05 - Coordinated public disclosure
ADDITIONAL INFORMATION
The information has been provided by iDefense.
The original article can be found at:
<http://www.idefense.com/intelligence/vulnerabilities/display.php?id=359>
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=359
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [TOOL] Hydra - A Parallelized Login Cracker
- Next by Date: [NT] McAfee Security Center MCINSCTL.DLL ActiveX Control File Overwrite
- Previous by thread: [TOOL] Hydra - A Parallelized Login Cracker
- Next by thread: [NT] McAfee Security Center MCINSCTL.DLL ActiveX Control File Overwrite
- Index(es):
Relevant Pages
- [NT] Unchecked Buffer in Content Management Server Could Enable Server Compromise
... Server product that simplifies developing and managing e-business web ... At
least one web page included with MCMS 2001 passes ... an attacker to overrun the
buffer. ... vulnerability would be to either cause MCMS to fail, ... (Securiteam) - [NT] Malformed Mail Attribute Causes Exchange 2000 to Exhaust CPU Resources
... To support the exchange of mail with heterogeneous systems, ... A security
vulnerability results because it is possible for an attacker to ... server would
remedy the denial of service. ... (Securiteam) - [NT] Unchecked Buffer in Network Share Provider Can Lead to Denial of Service
... SMB (Server Message Block) is the protocol Microsoft uses to share files, ...
The attacker could use both a user account and anonymous access to ... What's the scope
of the vulnerability? ... (Securiteam) - [NT] Unchecked Buffer in MDAC Function Could Enable SQL Server Compromise
... A security vulnerability results because the MDAC functions ... SQL
Server service to take actions dictated by the attacker. ... (Securiteam) - [NEWS] Multiple Vulnerabilities in Oracle Database (Character Conversion, Extproc, Password Disclosu
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Multiple vulnerabilities were
discovered in the (Oracle database server ... password is required to exploit this vulnerability.
... (Securiteam)