ID

VAR-200505-1218


CVE

CVE-2005-1254


TITLE

Ipswitch IMail IMAP SELECT Command denial of service vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200505-1195

DESCRIPTION

Stack-based buffer overflow in the IMAP server for Ipswitch IMail 8.12 and 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to cause a denial of service (crash) via a SELECT command with a large argument. Ipswitch IMail is prone to multiple remote vulnerabilities. Attackers may exploit these issues to deny service for legitimate users, obtaoin potentially sensitive information, and execute arbitrary code. The vulnerabilities include a directory-traversal issue, two remote denial-of-service issues, and multiple buffer-overflow issues. Ipswitch IMail server is a Windows-based communication and collaboration solution. However, this vulnerability cannot be further exploited. Ipswitch IMail IMAP SELECT Command DoS Vulnerability iDEFENSE Security Advisory 05.24.05 www.idefense.com/application/poi/display?id=241&type=vulnerabilities May 24, 2005 I. BACKGROUND Ipswitch IMail server is a Windows based messaging solution with a customer base of over 53 million users. More information about the application is available at: http://www.ipswitch.com/products/IMail_Server/index.html. II. The problem specifically exists in the handling of long arguments to the SELECT command. When a string approximately 260 bytes in size is supplied a stack-based buffer overflow occurs that results in an unhandled access violation forcing the daemon to exit. The issue is not believed to be further exploitable. III. ANALYSIS Successful exploitation allows remote to crash vulnerable IMAP servers and thereby prevent legitimate usage. The SELECT command is only available post authentication and therefore valid credentials are required to exploit this vulnerability IV. DETECTION iDEFENSE has confirmed the existence of this vulnerability in the latest version of Ipswitch IMAIL, version 8.13. Version 8.12 is also confirmed as vulnerable. It is suspected that earlier versions are vulnerable as well. V. WORKAROUND As this vulnerability is exploited after authentication occurs, ensuring that only trusted users have accounts can mitigate the risk somwhat. As a more effective workaround, consider limiting access to the IMAP server by filtering TCP port 143. If possible, consider disabling IMAP and forcing users to use POP3. VI. VENDOR RESPONSE The vendor has released the following patch to fix this vulnerability: ftp://ftp.ipswitch.com/Ipswitch/Product_Support/IMail/imail82hf2.exe The associated vendor advisory can be found at: http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf 2.html VII. CVE INFORMATION The Common Vulnerabilities and Exposures (CVE) project has assigned the name CAN-2005-1254 to this issue. This is a candidate for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems. VIII. DISCLOSURE TIMELINE 04/15/2005 Initial vendor notification 05/10/2005 Initial vendor response 05/24/2005 Coordinated public disclosure IX. CREDIT Sebastian Apelt is credited with this discovery. Get paid for vulnerability research http://www.idefense.com/poi/teams/vcp.jsp Free tools, research and upcoming events http://labs.idefense.com X. LEGAL NOTICES Copyright (c) 2005 iDEFENSE, Inc. Permission is granted for the redistribution of this alert electronically. It may not be edited in any way without the express written consent of iDEFENSE. If you wish to reprint the whole or any part of this alert in any other medium other than electronically, please email customerservice@idefense.com for permission. Disclaimer: The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties with regard to this information. Neither the author nor the publisher accepts any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Trust: 1.35

sources: NVD: CVE-2005-1254 // BID: 13727 // VULHUB: VHN-12463 // PACKETSTORM: 39314

AFFECTED PRODUCTS

vendor:ipswitchmodel:imailscope:eqversion:8.13

Trust: 1.9

vendor:ipswitchmodel:imailscope:eqversion:8.12

Trust: 1.6

vendor:ipswitchmodel:imailscope:lteversion:server_8.2_hotfix_2

Trust: 1.0

vendor:ipswitchmodel:imailscope:eqversion:server_8.2_hotfix_2

Trust: 0.6

vendor:ipswitchmodel:imail hotfixscope:eqversion:8.151

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:8.14

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:8.2

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:8.1

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:8.0.5

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:8.0.3

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.12

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.1

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.7

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.6

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.5

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.4

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.3

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.2

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.1

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.4

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.3

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.2

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.1

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0.6

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0.5

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0.4

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0.3

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0.2

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0.1

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:5.0.8

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:5.0.7

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:5.0.6

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:5.0.5

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:5.0

Trust: 0.3

vendor:ipswitchmodel:imail hotfixscope:neversion:8.22

Trust: 0.3

sources: BID: 13727 // CNNVD: CNNVD-200505-1195 // NVD: CVE-2005-1254

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2005-1254
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200505-1195
value: MEDIUM

Trust: 0.6

VULHUB: VHN-12463
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2005-1254
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-12463
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-12463 // CNNVD: CNNVD-200505-1195 // NVD: CVE-2005-1254

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2005-1254

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 39314 // CNNVD: CNNVD-200505-1195

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-200505-1195

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-12463

EXTERNAL IDS

db:NVDid:CVE-2005-1254

Trust: 2.1

db:BIDid:13727

Trust: 2.0

db:SECTRACKid:1014047

Trust: 1.7

db:CNNVDid:CNNVD-200505-1195

Trust: 0.7

db:IDEFENSEid:20050524 IPSWITCH IMAIL IMAP SELECT COMMAND DOS VULNERABILITY

Trust: 0.6

db:PACKETSTORMid:39314

Trust: 0.2

db:VULHUBid:VHN-12463

Trust: 0.1

sources: VULHUB: VHN-12463 // BID: 13727 // PACKETSTORM: 39314 // CNNVD: CNNVD-200505-1195 // NVD: CVE-2005-1254

REFERENCES

url:http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html

Trust: 2.0

url:http://www.securityfocus.com/bid/13727

Trust: 1.7

url:http://securitytracker.com/id?1014047

Trust: 1.7

url:http://www.idefense.com/application/poi/display?id=241&type=vulnerabilities

Trust: 1.7

url:http://www.ipswitch.com/products/imail_server/index.asp

Trust: 0.3

url:/archive/1/400543

Trust: 0.3

url:/archive/1/400542

Trust: 0.3

url:/archive/1/400546

Trust: 0.3

url:/archive/1/400541

Trust: 0.3

url:/archive/1/400545

Trust: 0.3

url:http://www.idefense.com/application/poi/display?id=241&type=vulnerabilities

Trust: 0.1

url:http://www.idefense.com/poi/teams/vcp.jsp

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2005-1254

Trust: 0.1

url:http://secunia.com/

Trust: 0.1

url:http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf

Trust: 0.1

url:http://cve.mitre.org),

Trust: 0.1

url:http://lists.grok.org.uk/full-disclosure-charter.html

Trust: 0.1

url:http://www.ipswitch.com/products/imail_server/index.html.

Trust: 0.1

url:http://labs.idefense.com

Trust: 0.1

sources: VULHUB: VHN-12463 // BID: 13727 // PACKETSTORM: 39314 // CNNVD: CNNVD-200505-1195 // NVD: CVE-2005-1254

CREDITS

Sebastian Apelt

Trust: 0.6

sources: CNNVD: CNNVD-200505-1195

SOURCES

db:VULHUBid:VHN-12463
db:BIDid:13727
db:PACKETSTORMid:39314
db:CNNVDid:CNNVD-200505-1195
db:NVDid:CVE-2005-1254

LAST UPDATE DATE

2024-08-14T14:22:56.529000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-12463date:2008-11-15T00:00:00
db:BIDid:13727date:2007-04-03T03:12:00
db:CNNVDid:CNNVD-200505-1195date:2005-10-20T00:00:00
db:NVDid:CVE-2005-1254date:2008-11-15T05:46:12.017

SOURCES RELEASE DATE

db:VULHUBid:VHN-12463date:2005-05-25T00:00:00
db:BIDid:13727date:2005-05-24T00:00:00
db:PACKETSTORMid:39314date:2005-08-14T20:34:55
db:CNNVDid:CNNVD-200505-1195date:2005-05-25T00:00:00
db:NVDid:CVE-2005-1254date:2005-05-25T04:00:00