Vissza a www.andrews.hu-ra

    [guru] MailEnable IMAP es POP szerviz javitasok


    DATE: Fri, 22 Dec 2006 11:20:19 +0100
    Több hibát találtak a MailEnable Microsoft Windows alapú levelző
    szerver IMAP és POP szervízeiben.
      * Buffer overflow az IMAP szervíz (MEIMAPS.exe) EXAMINE és SELECT
        parancsok argumentumkezelésében; a hiba kihasználásával tetszőleges
        kód futtatható.
      * Input ellenőrzési hiba az IMAP szervíz DELETE parancs
        argumentumkezelésében, mellyel a szervíz crash-elhető.
      * Stack-based buffer overflow érhető el speciális paraméterezésű parancs
        küldésével `Not Authenticated' állapotban az IMAP szervízben, mellyel
        tetszőleges kód futtatható.
      * Buffer overflow a POP szervíz PASS parancs argumentumkezelésében,
        mellyel szintén kód futtatható.
    
    Kiadták a javításokat.
    
    
    --- Begin Message ---
    ====================================================================== 
    
                         Secunia Research 30/11/2006
    
               - MailEnable IMAP Service Two Vulnerabilities -
    
    ====================================================================== 
    Table of Contents
    
    Affected Software....................................................1
    Severity.............................................................2
    Vendor's Description of Software.....................................3
    Description of Vulnerability.........................................4
    Solution.............................................................5
    Time Table...........................................................6
    Credits..............................................................7
    References...........................................................8
    About Secunia........................................................9
    Verification........................................................10
    
    ====================================================================== 
    1) Affected Software 
    
    MailEnable Professional Edition Version 2.32.
    
    NOTE: Other versions may also be affected.
    
    ====================================================================== 
    2) Severity 
    
    Rating: Moderately Critical
    Impact: System Access
            Denial of Service
    Where:  From Remote
    
    ====================================================================== 
    3) Vendor's Description of Software
    
    "MailEnable's mail server software provides a powerful, scalable
    hosted messaging platform for Microsoft Windows. MailEnable? offers
    stability, unsurpassed flexibility and an extensive feature set which
    allows you to provide cost-effective mail services."
    
    Product Link:
    http://www.mailenable.com/default.asp
    
    ====================================================================== 
    4) Description of Vulnerability
    
    Secunia Research has discovered two vulnerabilities in MailEnable,
    which can be exploited by malicious users to cause a DoS (Denial of
    service) or compromise a vulnerable system.
    
    1) A boundary error in the handling of arguments passed to the EXAMINE
    and SELECT commands within the IMAP service (MEIMAPS.EXE) can be
    exploited to cause a stack-based buffer overflow via an overly long
    argument.
    
    Successful exploitation allows execution of arbitrary code.
    
    2) An input validation error in the handling of arguments passed to
    the DELETE command within the IMAP service (MEIMAPS.EXE) can be
    exploited to cause a stack overflow and crash the service by sending
    an overly long argument consisting of "*" or "?" characters.
    
    ====================================================================== 
    5) Solution 
    
    Apply hotfix ME-10020:
    http://www.mailenable.com/hotfix/ME-10020.ZIP
    
    ====================================================================== 
    6) Time Table 
    
    27/11/2006 - Vendor notified.
    30/11/2006 - Vendor response with hotfix information.
    30/11/2006 - Public disclosure.
    
    ====================================================================== 
    7) Credits 
    
    Discovered by JJ Reyes, Secunia Research.
    
    ====================================================================== 
    8) References
    
    N/A
    
    ====================================================================== 
    9) About Secunia
    
    Secunia offers vulnerability management solutions to corporate
    customers with verified and reliable vulnerability intelligence
    relevant to their specific system configuration:
    
    http://corporate.secunia.com/
    
    Secunia also provides a publicly accessible and comprehensive advisory
    database as a service to the security community and private 
    individuals, who are interested in or concerned about IT-security.
    
    http://secunia.com/
    
    Secunia believes that it is important to support the community and to
    do active vulnerability research in order to aid improving the 
    security and reliability of software in general:
    
    http://corporate.secunia.com/secunia_research/33/
    
    Secunia regularly hires new skilled team members. Check the URL below to
    see currently vacant positions:
    
    http://secunia.com/secunia_vacancies/
    
    Secunia offers a FREE mailing list called Secunia Security Advisories:
    
    http://secunia.com/secunia_security_advisories/ 
    
    ====================================================================== 
    10) Verification 
    
    Please verify this advisory by visiting the Secunia website:
    http://secunia.com/secunia_research/2006-71/
    
    Complete list of vulnerability reports published by Secunia Research:
    http://secunia.com/secunia_research/
    
    ======================================================================
    
    
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    ======================================================================
    
                        Secunia Research 11/12/2006
    
          - MailEnable IMAP Service Buffer Overflow Vulnerability -
    
    ======================================================================
    Table of Contents
    
    Affected Software....................................................1
    Severity.............................................................2
    Vendor's Description of Software.....................................3
    Description of Vulnerability.........................................4
    Solution.............................................................5
    Time Table...........................................................6
    Credits..............................................................7
    References...........................................................8
    About Secunia........................................................9
    Verification........................................................10
    
    ======================================================================
    1) Affected Software 
    
    MailEnable Professional Edition Version 2.35.
    
    NOTE: Other versions may also be affected.
    
    ======================================================================
    2) Severity 
    
    Rating: Highly Critical
    Impact: System Access
    Where:  From Remote
    
    ======================================================================
    3) Vendor's Description of Software
    
    "MailEnable's mail server software provides a powerful, scalable
    hosted messaging platform for Microsoft Windows. MailEnable offers
    stability, unsurpassed flexibility and an extensive feature set which
    allows you to provide cost-effective mail services."
    
    Product Link:
    http://www.mailenable.com/default.asp
    
    ======================================================================
    4) Description of Vulnerability
    
    Secunia Research has discovered a vulnerability in MailEnable, which
    can be exploited by malicious people to compromise a vulnerable
    system.
    
    The vulnerability is caused due to a boundary error when processing
    data sent to the IMAP server. This can be exploited to cause a
    stack-based buffer overflow by first sending a command in the "Not
    Authenticated" state (e.g. "login" command) with a specially crafted
    parameter to make the IMAP service wait for more incoming data and
    then sending an overly long string (greater than 512 bytes).
    
    Successful exploitation allows execution of arbitrary code.
    
    ======================================================================
    5) Solution 
    
    Apply hotfix ME-10025:
    http://www.mailenable.com/hotfix/ME-10025.EXE
    
    ======================================================================
    6) Time Table 
    
    08/12/2006 - Vendor notified.
    08/12/2006 - Vendor response with hotfix information.
    11/12/2006 - Public disclosure.
    
    ======================================================================
    7) Credits 
    
    Discovered by JJ Reyes, Secunia Research.
    
    ======================================================================
    8) References
    
    The Common Vulnerabilities and Exposures (CVE) project has assigned 
    CVE-2006-6423 for the vulnerability.
    
    ======================================================================
    9) About Secunia
    
    Secunia offers vulnerability management solutions to corporate
    customers with verified and reliable vulnerability intelligence
    relevant to their specific system configuration:
    
    http://corporate.secunia.com/
    
    Secunia also provides a publicly accessible and comprehensive advisory
    database as a service to the security community and private 
    individuals, who are interested in or concerned about IT-security.
    
    http://secunia.com/
    
    Secunia believes that it is important to support the community and to
    do active vulnerability research in order to aid improving the 
    security and reliability of software in general:
    
    http://corporate.secunia.com/secunia_research/33/
    
    Secunia regularly hires new skilled team members. Check the URL below
    to see currently vacant positions:
    
    http://secunia.com/secunia_vacancies/
    
    Secunia offers a FREE mailing list called Secunia Security Advisories:
    
    http://secunia.com/secunia_security_advisories/ 
    
    ======================================================================
    10) Verification 
    
    Please verify this advisory by visiting the Secunia website:
    http://secunia.com/secunia_research/2006-73/
    
    Complete list of vulnerability reports published by Secunia Research:
    http://secunia.com/secunia_research/
    
    ======================================================================
    
    
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    ====================================================================== 
    
                         Secunia Research 18/12/2006
    
          - MailEnable POP Service "PASS" Command Buffer Overflow -
    
    ====================================================================== 
    Table of Contents
    
    Affected Software....................................................1
    Severity.............................................................2
    Vendor's Description of Software.....................................3
    Description of Vulnerability.........................................4
    Solution.............................................................5
    Time Table...........................................................6
    Credits..............................................................7
    References...........................................................8
    About Secunia........................................................9
    Verification........................................................10
    
    ====================================================================== 
    1) Affected Software 
    
    * MailEnable Enterprise Edition 2.35
    * MailEnable Professional Edition 2.35
    
    NOTE: Other versions may also be affected.
    
    ====================================================================== 
    2) Severity 
    
    Rating: Highly critical
    Impact: System Compromise
    Where:  Remote
    
    ====================================================================== 
    3) Vendor's Description of Software 
    
    "MailEnable's mail server software provides a powerful, scalable
    hosted messaging platform for Microsoft Windows. MailEnable? offers
    stability, unsurpassed flexibility and an extensive feature set which
    allows you to provide cost-effective mail services".
    
    Product Link:
    http://mailenable.com/
    
    ====================================================================== 
    4) Description of Vulnerability
    
    Secunia Research has discovered a vulnerability in MailEnable, which
    can be exploited by malicious people to compromise a vulnerable
    system.
    
    The vulnerability is caused due to a boundary error in the POP service
    when handling arguments passed to the "PASS" command. This can be
    exploited to cause a stack-based buffer overflow by passing an overly
    long, specially crafted string as argument to the affected command.
    
    Successful exploitation allows execution of arbitrary code.
    
    ====================================================================== 
    5) Solution 
    
    Apply hotfix:
    http://www.mailenable.com/hotfix/ME-10026.EXE
    
    ====================================================================== 
    6) Time Table 
    
    18/12/2006 - Vendor notified.
    18/12/2006 - Vendor response and hotfix released.
    18/12/2006 - Public disclosure.
    
    ====================================================================== 
    7) Credits 
    
    Discovered by Carsten Eiram, Secunia Research.
    
    ====================================================================== 
    8) References
    
    The Common Vulnerabilities and Exposures (CVE) project has assigned 
    CVE-2006-6605 for the vulnerability.
    
    ====================================================================== 
    9) About Secunia
    
    Secunia offers vulnerability management solutions to corporate
    customers with verified and reliable vulnerability intelligence
    relevant to their specific system configuration:
    
    http://corporate.secunia.com/
    
    Secunia also provides a publicly accessible and comprehensive advisory
    database as a service to the security community and private 
    individuals, who are interested in or concerned about IT-security.
    
    http://secunia.com/
    
    Secunia believes that it is important to support the community and to
    do active vulnerability research in order to aid improving the 
    security and reliability of software in general:
    
    http://corporate.secunia.com/secunia_research/33/
    
    Secunia regularly hires new skilled team members. Check the URL below to
    see currently vacant positions:
    
    http://secunia.com/secunia_vacancies/
    
    Secunia offers a FREE mailing list called Secunia Security Advisories:
    
    http://secunia.com/secunia_security_advisories/ 
    
    ====================================================================== 
    10) Verification 
    
    Please verify this advisory by visiting the Secunia website:
    http://secunia.com/secunia_research/2006-75/
    
    Complete list of vulnerability reports published by Secunia Research:
    http://secunia.com/secunia_research/
    
    ======================================================================
    
    
    
    
    
    
    

    --- End Message ---

    Vissza a www.andrews.hu-ra