MDaemon IMAP Server Mail Folder Name Format String
Medium Nessus Plugin ID 20987
SynopsisThe remote IMAP server is affected by a format string vulnerability.
DescriptionThe remote host is running Alt-N MDaemon, an SMTP/IMAP server for the Windows operating system family.
The IMAP server component of MDaemon is affected by a format string vulnerability involving folders with format string specifiers in their names . An authenticated attacker can leverage this issue to cause the remote host to consume excessive CPU resources.
Further, given the nature of format string vulnerabilities, this issue is likely to lead to the execution of arbitrary code as LOCAL SYSTEM.
SolutionUpgrade to MDaemon 8.15 or later.