vendor:
NetMail
by:
MC
N/A
CVSS
N/A
Buffer Overflow
119
CWE
Product Name: NetMail
Affected Version From: Novell NetMail 3.52
Affected Version To: Novell NetMail 3.52d
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2007
Novell NetMail <=3.52d IMAP AUTHENTICATE Buffer Overflow
This module exploits a stack buffer overflow in Novell's NetMail 3.52 IMAP AUTHENTICATE GSSAPI command. By sending an overly long string, an attacker can overwrite the buffer and control program execution. Using the PAYLOAD of windows/shell_bind_tcp or windows/shell_reverse_tcp allows for the most reliable results.
Mitigation:
N/A