vendor:
WorldMail
by:
Muhammad Alharmeel
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: WorldMail
Affected Version From: 9.0.333.0
Affected Version To: 9.0.333.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows Server 2003 SP1
Pre Authentication Buffer Overflow in Eudora Qualcomm WorldMail 9.0.333.0 IMAPd Service
Pre Authentication Buffer Overflow in Eudora Qualcomm WorldMail 9.0.333.0 IMAPd Service. The SEH gets overwritten at 749 bytes when using the UID command. Only 79 bytes left after SEH, so the shellcode was placed before SEH and a backward jump is used after SEH to execute the shellcode. Shellcode used is shell_bind_tcp LPORT*4444 EXITFUNC*seh, with bad characters 0x00 and 0x7b.
Mitigation:
Apply the latest security patches and updates from the vendor.