Mercury IMAP Server LOGIN Command Remote Overflow
High Nessus Plugin ID 24785
SynopsisThe remote IMAP server is affected by a buffer overflow vulnerability.
DescriptionThe remote host is running the Mercury Mail Transport System, a free suite of server products for Windows and NetWare associated with Pegasus Mail.
The remote installation of Mercury Mail includes an IMAP server that is affected by a buffer overflow flaw. Using a specially crafted LOGIN command, an unauthenticated, remote attacker can leverage this issue to crash the remote application and even execute arbitrary code remotely, subject to the privileges under which the application runs.
SolutionUnknown at this time.