73 Courier IMAP up to 3.0.0 buffer overflow Misc 2004/03/22 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.2 Corrected the plugin structure and added the accuracy values in 1.2 tcp 143 open|sleep|close|pattern_exists OK Courier-IMAP ready. 60 Check is copied from the Nessus plugin. Courier-Imap up to 3.0.0 Courier-Imap 3.0.0 and newer Buffer Overflow The remote mail server is the Courier-IMAP imap server. There is a buffer overflow in the conversions functions of this softwarewhich may allow an attacker to execute arbitrary code on this host. Upgrade to version 3.0.0 or newer. Limit unwanted connections and communications with firewalling. 1 hour Yes http://www.securityfocus.com/bid/9845/exploit/ Yes Yes High 6 6 9 7 High Nessus is able to do the same check. 9845 12103 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.computec.ch