Mercury Mail Multiple Remote IMAP Stack Buffer Overflow Vulnerabilities

Mercury Mail is reported susceptible to multiple stack-based buffer-overflow vulnerabilities in its IMAP server implementation. These issues are due to the application's failure to properly bounds-check user-supplied input before copying it to a finite-sized memory buffer.

Exploiting these vulnerabilities allows authenticated, remote attackers to execute arbitrary machine code in the context of the affected server process.

Versions prior to 4.01a of Mercury Mail are reported affected by these vulnerabilities; other versions may also be affected.

Note: BID 11788 has been consolidated with this BID; they actually represent the same issues.


 

Privacy Statement
Copyright 2010, SecurityFocus