vendor:
Mercur Messaging 2005 SP3
by:
muts@offensive-security.com
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Mercur Messaging 2005 SP3
Affected Version From: Mercur Messaging 2005 SP3
Affected Version To: Mercur Messaging 2005 SP3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
Mercur Messaging 2005 SP3 IMAP service – Egghunter mod
The exploit allows for injecting a buffer of more than 2000 bytes using an IMAP command, specifically the LIST command. This buffer is then used to execute an egghunter which locates the shellcode in memory and executes it. The exploit also includes a bindshell payload that listens on port 4444.
Mitigation:
Apply the latest patch or update for the Mercur Messaging 2005 SP3 IMAP service.