E-Post IMAP APPEND denial of service
| epost-imap-append-dos (24341) |
Description:
E-Post Mail Server Enterprise, E-Post Mail Server, E-Post SMTP Server Enterprise, E-Post SMTP Server, and SPA-PRO Mail @Solomon Enterprise are vulnerable to a denial of service caused by improper handling of the APPEND command in the IMAP service.. A remote attacker could send an APPEND command and terminate the connection before sending the required data to cause the IMAP service to consume a large amount of CPU resources.
Platforms Affected:
- e-Post, E-Post Mail Server 4.10
- e-Post, E-Post Mail Server Enterprise 4.10
- e-Post, E-Post SMTP Server 4.10
- e-Post, E-Post SMTP Server Enterprise 4.10
- e-Post, SPA-PRO Mail @Solomon 4.00
- e-Post, SPA-PRO Mail @Solomon Enterprise 4.00
- e-Post, SPA-PRO SMTP @Solomon 4.00
Remedy:
Apply the appropriate patch as listed in the Secunia Security Advisory: SA18480. See References.
Consequences:
Denial of Service
References:
- E-Post Web site, E-Post Web site at http://www.e-postinc.jp/download.html. (Site in Japanese)
- BID-16379: E-Post MailServer Multiple Remote Vulnerabilities
- CVE-2006-0449: Early termination vulnerability in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allows remote attackers to cause a denial of service (infinite loop) by sending an APPEND command and disconnecting before the expected amount of data is sent.
- OSVDB ID: 22766: E-Post Multiple Product IMAP APPEND Command Infinite Loop DoS
- SA18480: E-Post Mail Server Products Multiple Vulnerabilities
- VUPEN/ADV-2006-0318: E-Post Mail Products Buffer Overflow and Denial of Service Vulnerabilities
Reported:
Jan 25, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
