Description
Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server.
Affected products
- atrium_software / mercur_mailserver3.3 – 3.3
- atrium_software / mercur_mailserver3.3_sp1 – 3.3_sp1
- atrium_software / mercur_mailserver3.3_sp2 – 3.3_sp2
- atrium_software / mercur_mailserver4.1 – 4.1
- atrium_software / mercur_mailserver4.1_sp1 – 4.1_sp1
- atrium_software / mercur_mailserver4.2 – 4.2
- atrium_software / mercur_mailserver4.2_sp1 – 4.2_sp1
- atrium_software / mercur_mailserver4.2_sp2 – 4.2_sp2
References
- MISChttp://www.securityfocus.com/bid/8861
- VENDOR_ADVISORYhttp://secunia.com/advisories/10038
- MISChttp://www.securityfocus.com/bid/8889
- MISChttp://www.osvdb.org/2688
- MISChttp://archives.neohapsis.com/archives/fulldisclosure/2003-q4/1459.html
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/13468
- MISChttp://www.atrium-software.com/mail%20server/pub/mcr42sp3a.html
- MISChttp://www.securiteam.com/windowsntfocus/6U00N1P8KC.html