Search:     Advanced search
server monitoring

Mercury SMTP Server AUTH CRAM-MD5 Remote Buffer Overflow

Article ID: 25928
Last updated: 27 Jan, 2009
Views: 530
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Mercury SMTP Server AUTH CRAM-MD5 Remote Buffer Overflow

This script is Copyright (C) 2007-2008 Tenable Network Security, Inc.

FamilySMTP problems
Plugin ID25928
Bugtraq ID25357
CVE IDCVE-2007-4440

Description:

Synopsis :

The remote mail server is affected by a buffer overflow vulnerability.

Description :

The remote host is running the Mercury Mail Transport System, a free
suite of server products for Windows and Netware associated with
Pegasus Mail.

The version of Mercury Mail installed on the remote host includes an
SMTP server that is affected by a buffer overflow flaw. Using a
specially-crafted AUTH CRAM-MD5 request, an unauthenticated remote
attacker can leverage this issue to crash the remote application and
even execute arbitrary code remotely, subject to the privileges under
which the application runs.

See also :

http://www.milw0rm.com/exploits/4294
http://www.security-express.com/archives/fulldisclosure/2007-08/0341.html
http://community.pmail.com/forums/thread/3816.aspx
http://www.pmail.com/m32_451.htm

Solution :

Upgrade to Mercury/32 v4.52 or later or apply the 4.01c / 1.49
security patch.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
This article was:   Helpful | Not Helpful
Prev   Next
Port scanners     smtpscan