vendor:
IMail Server
by:
ZhenHan.Liu
7.5
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: IMail Server
Affected Version From: Ipswitch IMail Server 2006 version 6.8.8.1
Affected Version To: Ipswitch IMail Server 2006 version 6.8.8.1
Patch Exists: NO
Related CWE:
CPE: a:ipswitch:imail_server:2006:6.8.8.1
Platforms Tested: Windows
2007
Ipswitch IMail Server 2006 IMAP SEARCH COMMAND Stack Overflow Exploit
This exploit targets a stack overflow vulnerability in Ipswitch IMail Server 2006. The vulnerability allows an attacker to execute arbitrary code by sending a specially crafted IMAP SEARCH COMMAND. The vulnerable code can be found in the imap4d32.exe file, version 6.8.8.1. The exploit takes advantage of a buffer overflow in the code, causing it to overwrite the return address and execute the attacker's payload.
Mitigation:
Upgrade to a non-vulnerable version of Ipswitch IMail Server.