vendor:
MDaemon
by:
Rootshell
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: MDaemon
Affected Version From: MDaemon 2.71 SP1
Affected Version To: MDaemon 2.71 SP1
Patch Exists: YES
Related CWE: N/A
CPE: a:alt-n_technologies:mdaemon
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
1998
Alt-N MDaemon Server SMTP HELO Command Argument Buffer Overflow Vulnerability
It has been reported that Alt-N MDaemon server is prone to an SMTP HELO command argument buffer overflow vulnerability. The issue presents itself likely due to insufficient bounds checking performed when handling malicious SMTP HELO command arguments of excessive length. It has been reported that a remote attacker may exploit this condition to trigger a denial of service in the affected daemon.
Mitigation:
Apply the latest security patches and updates to the affected system.