Memory-leak vulnerability in EServ/3.00

From: d4rkgr3y (d4rk_at_securitylab.ru)
Date: 11/01/03

  • Next message: bob: "Re: New Varient Of Irc Worm Spreading"
    To: bugtraq@securityfocus.com
    Date: Sat, 1 Nov 2003 12:04:08 +0300
    
    

    /**********************************************************
    *
    * m00 security advistory #005
    *
    * Memory-leak vulnerability in EServ/3.00
    *
    * www.m00security.org
    *
    ************************************************************/

    ---------------------------------
    Product: eServ
    Version: 2.95-3.00
    OffSite: www.eserv.ru
    ---------------------------------

    Overview:

    eServ includes Mail, News, Web, FTP and Proxy Servers.
    It's the most popular russian server.

    Problem description:

    Several time ago similar vulnerability was founded in EServ/2.99
    by SECURITEAM. It was noted, that EServ doesn't free
    alocated memory in the heap after each disconnect. We have discovered
    that similar problem exists in newest version of EServ.
    It's possible to kill EServ and freeze the whole system by sending
    a lot of data to EServ HTTP-service.
    We have tested this vulnerability in LAN against win2k. EServ ate
    all virtual-memory with total speed 10mb/s.

    Exploit:

    Remote Denial-of-Service exploit (*nix and win32 versions) against
    EServ/2.95-3.0 you can find on our official site: m00.void.ru

    Solution:

    Vendor was informated about vulnerability.
    Patched EServ/2.99 u can find here:
    ftp://ftp.eserv.ru/pub/beta/2.99/Eserv3463.zip

    (c) m00 Security / m00.void.ru


  • Next message: bob: "Re: New Varient Of Irc Worm Spreading"

    Relevant Pages

    • [NT] EServ Password Protected File Arbitrary Read Access Vulnerability
      ... EServ is a Mail, News, Web, FTP, and Proxy Server ... A vulnerability in the product allows ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)
    • [Full-Disclosure] eServ Memory Leak Solution
      ... the cause and solution of the eServ ... but cannot be exploited to cause major memory loss. ... eServ has had one other vulnerability, a buffer overrun in its virtual host ... I was also informed during discussions with the developer that the reason ...
      (Full-Disclosure)
    • eServ Memory Leak Solution
      ... the cause and solution of the eServ ... but cannot be exploited to cause major memory loss. ... eServ has had one other vulnerability, a buffer overrun in its virtual host ... I was also informed during discussions with the developer that the reason ...
      (Bugtraq)
    • Eserv 2.97 Password Protected File Arbitrary Read Access Vulnerability
      ... Eserv 2.97 Password Protected File Arbitrary Read Access ... The vulnerability allows you to view any password protected files and ... PGP Key ID: 0x2B5EDCB0 Fingerprint: ...
      (Bugtraq)