MDaemon IMAP Server Mail Folder Name Format String

Medium Nessus Plugin ID 20987


The remote IMAP server is affected by a format string vulnerability.


The remote host is running Alt-N MDaemon, an SMTP/IMAP server for the Windows operating system family.

The IMAP server component of MDaemon is affected by a format string vulnerability involving folders with format string specifiers in their names . An authenticated attacker can leverage this issue to cause the remote host to consume excessive CPU resources.

Further, given the nature of format string vulnerabilities, this issue is likely to lead to the execution of arbitrary code as LOCAL SYSTEM.


Upgrade to MDaemon 8.15 or later.

See Also

Plugin Details

Severity: Medium

ID: 20987

File Name: mdaemon_imap_format_string.nasl

Version: $Revision: 1.17 $

Type: remote

Agent: windows

Family: Windows

Published: 2006/02/28

Modified: 2017/06/06

Dependencies: 17975

Risk Information

Risk Factor: Medium


Base Score: 5

Temporal Score: 4.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Temporal Vector: CVSS2#E:POC/RL:U/RC:ND

Vulnerability Information

Required KB Items: imap/login, imap/password

Excluded KB Items: imap/false_imap

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 2006/02/20

Reference Information

CVE: CVE-2006-0925

BID: 16854

OSVDB: 23477