vendor:
Mercury Mail Transport System
by:
MC
7.5
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: Mercury Mail Transport System
Affected Version From: 4.51
Affected Version To: 4.51
Patch Exists: NO
Related CWE: CVE-2007-4440
CPE: a:mercury:mail_transport_system:4.51
Platforms Tested: Windows
2007
Mercury Mail SMTP AUTH CRAM-MD5 Buffer Overflow
This module exploits a stack buffer overflow in Mercury Mail Transport System 4.51. By sending a specially crafted argument to the AUTH CRAM-MD5 command, an attacker may be able to execute arbitrary code.
Mitigation:
Apply vendor patches and update to the latest version of Mercury Mail Transport System.