73
Courier IMAP up to 3.0.0 buffer overflow
Misc
2004/03/22
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.2
Corrected the plugin structure and added the accuracy values in 1.2
tcp
143
open|sleep|close|pattern_exists OK Courier-IMAP ready.
60
Check is copied from the Nessus plugin.
Courier-Imap up to 3.0.0
Courier-Imap 3.0.0 and newer
Buffer Overflow
The remote mail server is the Courier-IMAP imap server. There is a buffer overflow in the conversions functions of this softwarewhich may allow an attacker to execute arbitrary code on this host.
Upgrade to version 3.0.0 or newer. Limit unwanted connections and communications with firewalling.
1 hour
Yes
http://www.securityfocus.com/bid/9845/exploit/
Yes
Yes
High
6
6
9
7
High
Nessus is able to do the same check.
9845
12103
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch