vendor:
DMS POP3 Server
by:
milw0rm.com
7.5
CVSS
HIGH
Buffer Overflow
121
CWE
Product Name: DMS POP3 Server
Affected Version From: Windows 2000/XP 1.5.3 build 37
Affected Version To: Unknown
Patch Exists: YES
Related CWE:
CPE: a:dms:dms_pop3_server:1.5.3
Platforms Tested:
2004
DMS POP3 Server Overflow
This script exploits a buffer overflow vulnerability in the DMS POP3 Server for Windows 2000/XP version 1.5.3 build 37. By sending a long string of 'A' characters as the username, it crashes the server and potentially allows for remote code execution. The exploit attempts to kill the DMS POP3 service by sending the malicious username and then checks if the service is still running. This vulnerability was discovered in 2004.
Mitigation:
Apply the patch provided by the vendor to fix the buffer overflow vulnerability. The patch can be downloaded from the vendor's website at http://www.digitalmapping.sk.ca/pop3srv/Update.asp.