Freedom The Open Source Way Contribute Articles or News to OSForgeOSForge HomeLogout from Forums
Contacting OSForgeOSForge HomeAbout OSForge
  

Root
Contribute News
Learning Corner
Linux Distributions
Linux Common FAQ's
Discussion Forums
Community Gallery
Links Directory
Search OSForge
Networking
Industry Updates
Linux & Open Source
Opinions
Press Release
Programming
Security
Web Development

White Paper
Plat'Home Unveils Winners of “Will Linux Work?” Contest
Zenoss Core Recognized as Best Open Source Network Monitoring Solution
LinMin™ Joins Intel® Certified Software Solutions Program
xTuple™ ERP 3.0 Wins “Best Business Application” At LinuxWorld Conference & Exp
Holland Computing Center - Rocks+Moab Provides Windows/Linux Cluster Solution
LogMeIn Launches Mobile Plug-in for Linux
FuseMail Selects Funambol’s Open Source Push Email and PIM Sync Solution
Zenoss Expands IT Management Solution for Managed Service Providers
Moab Workload Manager Claims Title as World’s First Petaflop Scheduler

View More

IMAP buffer overflow
By : Eric Lim [www] Find more article by Eric Lim on Security
Tuesday the 28th, May 2002 at 07:30 AM (EDT)
Send this Story to a Friend Readers TalkBack (0) - 696 Reads

Printer Friendly Page Printable format
Send this Story to a Friend Foward to Email

IMAP buffer overflow.

Problem description:

  UW imapd version 2000c and older have a buffer overflow that allows a
  malicious user to send a malformed request that enables that user to
  run commands on the server with that user's UID and GID. This issue
  does not gain the attacker root privileges from a normal user login as
  the user must have already successfully logged into the imapd service.
  This exploit mainly affects email servers where the user has IMAP access
  but no shell access.

-------------------------------------------------------------------------
Updated packages:

  6bd290e533eced8f4c56acb450844f39  imap-2001a-2.src.rpm

  4a51e33caf7d64208bc3a33e849bd360  imap-2001a-2.i386.rpm
  32423cd94780d2e52cc018f2949fa333  imap-devel-2001a-2.i386.rpm

-------------------------------------------------------------------------
References:

  http://marc.theaimsgroup.com/?l=bugtraq&m=102107222100529
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0379

=========================================================================

Packages available from ftp://ftp.eridani.co.uk/pub/Aeryn/
or by HTTP from http://ftp.eridani.co.uk/

Packages are signed with our GNU GPG key, also on our FTP site.

Users of releases of Eridani Linux prior to 6.3 are advised to download  
the source RPM and rebuild for their system.

Copyright (C)2002 Eridani Star System

  
Reader Rating from 1-5

 

Poor very 

1

2

3

4

5
 very Excellent

Talkback

Post Your Talkback | View All Talkback (0 Posted)


 Currently there are no Talkback posted on "IMAP buffer overflow", Click here to be the first to post a talkback.


 
Scroll Up

   About | Term of Use | Privacy | Contact us | Tell a Friend | Advertise  

OSForge News RSS Feed