[NT] IPSwitch IMail Server IMail Client Buffer Overflow



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



IPSwitch IMail Server IMail Client Buffer Overflow
------------------------------------------------------------------------


SUMMARY

The <http://www.ipswitch.com/purchase/products/imail_server.asp> IMail
Client "is provided for those who are administering IMail Server on the NT
workstation on which IMail Server is installed. It is useful for reading
the 'root' mailbox, working with seldom-used accounts, and testing.".
Secunia Research has discovered a vulnerability in the IMail Client, which
potentially can be exploited by malicious people to compromise a user's
system.

DETAILS

Vulnerable Systems:
* IMail Client version 9.22 included with IPSwitch IMail Server version
2006.22

The vulnerability is caused due to a boundary error within the IMail
Client when processing emails containing multipart MIME data. This can be
exploited to cause a data segment-based buffer overflow via an overly long
"boundary" parameter (more than 212 bytes).

Solution:
The vendor recommends users to delete the IMail Client application, which
will be removed from the next major release of the IPSwitch IMail Server.

Time Table:
24/09/2007 - Vendor notified.
25/09/2007 - Vendor response.
30/10/2007 - Public disclosure.

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4345>
CVE-2007-4345


ADDITIONAL INFORMATION

The information has been provided by Secunia Research.
The original article can be found at:
<http://secunia.com/secunia_research/2007-81/>
http://secunia.com/secunia_research/2007-81/



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [EXPL] Ipswitch IMail LDAP Remote Exploit (Improved)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... a vulnerability in Ipswitch's IMail ... void usage(); ... unsigned int IMAIL6_7=60; ...
    (Securiteam)
  • [EXPL] Imail Buffer Overflow Exploit (RCPT TO)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Imail Buffer Overflow Exploit ... send $socket, $request, 0; ...
    (Securiteam)
  • Re: Routing with Imail
    ... If Imail uses an LDAP directory and IMAP4 mailboxes, ... Migration Wizard that ships with Exchange 2003. ... You will select this option from the Migration Wizard, ... > His actual e-mails are on an IMail server. ...
    (microsoft.public.exchange.connectivity)
  • IPSwitch IMail ADVISORY/EXPLOIT/PATCH
    ... "In 1995, Ipswitch released IMail Server, the first ... as none of the registers point to our payload on ret ... right over our chosen ret (call/jmp esp).. ...
    (Bugtraq)
  • Re[2]: [VulnWatch] IMail Account hijack through the Web Interface
    ... Z> a bullet proof workaround but can help to ... when using HTTPS to access your IMail ... >> deploy and cumbersome to administer, IMail Server is easy ... >> session authentication is maintained via a unique URL. ...
    (Bugtraq)