Mercury IMAP Server SEARCH Command Remote Buffer Overflow

medium Nessus Plugin ID 26067

Synopsis

The remote IMAP server is affected by a buffer overflow vulnerability.

Description

The remote host is running the Mercury Mail Transport System, a free suite of server products for Windows and NetWare associated with Pegasus Mail.

The remote installation of Mercury Mail includes an IMAP server that is affected by a buffer overflow vulnerability. Using a specially- crafted SEARCH command, an authenticated, remote attacker can leverage this issue to crash the remote application and even execute arbitrary code remotely, subject to the privileges under which the application runs.

Solution

Unknown at this time.

Plugin Details

Severity: Medium

ID: 26067

File Name: mercury_imap_search_overflow.nasl

Version: 1.18

Type: remote

Published: 9/20/2007

Updated: 7/14/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Information

Required KB Items: imap/login, imap/password

Exploit Available: true

Exploit Ease: Exploits are available

Reference Information

CVE: CVE-2007-5018

BID: 25733

CWE: 119