Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Bugtraq: RE: Remote Buffer Overflow in MailEnable HTTPMail

RE: Remote Buffer Overflow in MailEnable HTTPMail

From: MailEnable Sales <info_at_mailenable.com>
Date: Sun, 16 May 2004 22:29:08 +1000

Hi,

Thanks for the email. This error was not an overflow issue but a bug in the
service (i.e. the error would cause the service to stop, but could the
exploiter could not exploit this further or run code on the server).

A fix for the bug can be found at:

http://www.mailenable.com/hotfix

Thanks
Peter Fregon
MailEnable Pty. Ltd.

-----Original Message-----
From: Oliver_at_greyhat.de [mailto:Oliver_at_greyhat.de]
Sent: Saturday, 15 May 2004 10:41 PM
To: bugtraq_at_securityfocus.com
Cc: info_at_mailenable.com
Subject: Remote Buffer Overflow in MailEnable HTTPMail

Regarding to the heap overflow vulnerability of MailEnable HTTPMail
(http://www.securityfocus.com/bid/10312), i installed the latest hotfix
(http://mailenable.com/hotfix/MEHTTPS.zip), and found an additional
overflow.

Sending a request like:

c:\telnet localhost 8080
   GET / HTTP/1.0
   Authorization: A

Crashes the services. The overflow seems to occur in the Authorization
header variable. A single character will lead to the crash.

I did no further research in order to fully exploit this vuln. A more
detailed readme can be found on my website:
www.oliverkarow.de/research/MailWebHTTPAuthCrash.txt
Received on May 17 2004

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]