ID

VAR-200505-1219


CVE

CVE-2005-1255


TITLE

Ipswitch IMail IMAP SELECT Command denial of service vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200505-1200

DESCRIPTION

Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a long username argument or (2) a long username argument that begins with a special character. Ipswitch IMail is prone to multiple remote vulnerabilities. Attackers may exploit these issues to deny service for legitimate users, obtaoin potentially sensitive information, and execute arbitrary code. The vulnerabilities include a directory-traversal issue, two remote denial-of-service issues, and multiple buffer-overflow issues. Attackers can use this vulnerability to cause the target service to crash. However, this vulnerability cannot be further exploited. Ipswitch IMail IMAP LOGIN Remote Buffer Overflow Vulnerabilities iDEFENSE Security Advisory 05.24.05 www.idefense.com/application/poi/display?id=243&type=vulnerabilities May 24, 2005 I. BACKGROUND Ipswitch Collaboration Suite (ICS) is a comprehensive communication and collaboration solution for Microsoft Windows with a customer base of over 53 million users. More information is available on the vendor's website: http://www.ipswitch.com/products/IMail_Server/index.html II. The first vulnerability specifically exists in the handling of a long username to the LOGIN command. A long username argument of approximately 2,000 bytes will cause a stack based unicode string buffer overflow providing the attacker with partial control over EIP. As this vulnerability is in the LOGIN command itself, valid credentials are not required. The second vulnerability also exists in the handling of the LOGIN command username argument, however it lends itself to easier exploitation. If a large username starting with one of several special characters is specified, a stack overflow occurs, allowing an attacker to overwrite the saved instruction pointer and control execution flow. Included in the list of special characters are the following: % : * @ & Both of these vulnerabilities can lead to the execution of arbitrary code. III. Valid credentials are not required to for exploitation, which heightens the impact of this vulnerability. IV. DETECTION iDEFENSE has confirmed the existence of this vulnerability in the latest version of Ipswitch IMAIL, version 8.13. Version 8.12 is also confirmed as vulnerable. It is suspected that earlier versions are also vulnerable. V. WORKAROUND As this vulnerability is exploited before authentication occurs, the only effective workaround is to limit access to the IMAP server by filtering TCP port 143. If possible, consider disabling IMAP and forcing users to use POP3. VI. VENDOR RESPONSE The vendor has released the following patch to fix this vulnerability: ftp://ftp.ipswitch.com/Ipswitch/Product_Support/IMail/imail82hf2.exe The associated vendor advisory can be found at: http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf 2.html VII. CVE INFORMATION The Common Vulnerabilities and Exposures (CVE) project has assigned the name CAN-2005-1255 to this issue. This is a candidate for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems. VIII. DISCLOSURE TIMELINE 04/25/2005 Initial vendor notification 05/10/2005 Initial vendor response 05/24/2005 Public disclosure IX. CREDIT The discoverer of the first vulnerability wishes to remain anonymous. iDEFENSE Labs is credited with the discovery of the second vulnerability. Get paid for vulnerability research http://www.idefense.com/poi/teams/vcp.jsp Free tools, research and upcoming events http://labs.idefense.com X. LEGAL NOTICES Copyright (c) 2005 iDEFENSE, Inc. Permission is granted for the redistribution of this alert electronically. It may not be edited in any way without the express written consent of iDEFENSE. If you wish to reprint the whole or any part of this alert in any other medium other than electronically, please email customerservice@idefense.com for permission. Disclaimer: The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties with regard to this information. Neither the author nor the publisher accepts any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Trust: 1.35

sources: NVD: CVE-2005-1255 // BID: 13727 // VULHUB: VHN-12464 // PACKETSTORM: 39312

AFFECTED PRODUCTS

vendor:ipswitchmodel:imailscope:eqversion:8.13

Trust: 1.9

vendor:ipswitchmodel:imailscope:eqversion:8.12

Trust: 1.6

vendor:ipswitchmodel:collaboration suitescope:eqversion:*

Trust: 1.0

vendor:ipswitchmodel:imail serverscope:lteversion:8.2_hotfix_2

Trust: 1.0

vendor:ipswitchmodel:imail serverscope:eqversion:8.2_hotfix_2

Trust: 0.6

vendor:ipswitchmodel:collaboration suitescope: - version: -

Trust: 0.6

vendor:ipswitchmodel:imail hotfixscope:eqversion:8.151

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:8.14

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:8.2

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:8.1

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:8.0.5

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:8.0.3

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.12

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.1

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.7

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.6

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.5

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.4

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.3

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.2

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:7.0.1

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.4

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.3

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.2

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.1

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0.6

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0.5

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0.4

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0.3

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0.2

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0.1

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:6.0

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:5.0.8

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:5.0.7

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:5.0.6

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:5.0.5

Trust: 0.3

vendor:ipswitchmodel:imailscope:eqversion:5.0

Trust: 0.3

vendor:ipswitchmodel:imail hotfixscope:neversion:8.22

Trust: 0.3

sources: BID: 13727 // CNNVD: CNNVD-200505-1200 // NVD: CVE-2005-1255

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2005-1255
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200505-1200
value: CRITICAL

Trust: 0.6

VULHUB: VHN-12464
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2005-1255
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-12464
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-12464 // CNNVD: CNNVD-200505-1200 // NVD: CVE-2005-1255

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2005-1255

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 39312 // CNNVD: CNNVD-200505-1200

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-200505-1200

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-12464

EXTERNAL IDS

db:NVDid:CVE-2005-1255

Trust: 2.1

db:BIDid:13727

Trust: 2.0

db:SECTRACKid:1014047

Trust: 1.7

db:CNNVDid:CNNVD-200505-1200

Trust: 0.7

db:IDEFENSEid:20050524 IPSWITCH IMAIL IMAP LOGIN REMOTE BUFFER OVERFLOW VULNERABILITIES

Trust: 0.6

db:PACKETSTORMid:39312

Trust: 0.2

db:SEEBUGid:SSVID-63181

Trust: 0.1

db:EXPLOIT-DBid:1124

Trust: 0.1

db:EXPLOIT-DBid:3627

Trust: 0.1

db:EXPLOIT-DBid:1035

Trust: 0.1

db:VULHUBid:VHN-12464

Trust: 0.1

sources: VULHUB: VHN-12464 // BID: 13727 // PACKETSTORM: 39312 // CNNVD: CNNVD-200505-1200 // NVD: CVE-2005-1255

REFERENCES

url:http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html

Trust: 2.0

url:http://www.securityfocus.com/bid/13727

Trust: 1.7

url:http://securitytracker.com/id?1014047

Trust: 1.7

url:http://www.idefense.com/application/poi/display?id=243&type=vulnerabilities

Trust: 1.7

url:http://www.ipswitch.com/products/imail_server/index.asp

Trust: 0.3

url:/archive/1/400543

Trust: 0.3

url:/archive/1/400542

Trust: 0.3

url:/archive/1/400546

Trust: 0.3

url:/archive/1/400541

Trust: 0.3

url:/archive/1/400545

Trust: 0.3

url:http://www.idefense.com/application/poi/display?id=243&type=vulnerabilities

Trust: 0.1

url:http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2005-1255

Trust: 0.1

url:http://www.idefense.com/poi/teams/vcp.jsp

Trust: 0.1

url:http://secunia.com/

Trust: 0.1

url:http://www.ipswitch.com/products/imail_server/index.html

Trust: 0.1

url:http://cve.mitre.org),

Trust: 0.1

url:http://lists.grok.org.uk/full-disclosure-charter.html

Trust: 0.1

url:http://labs.idefense.com

Trust: 0.1

sources: VULHUB: VHN-12464 // BID: 13727 // PACKETSTORM: 39312 // CNNVD: CNNVD-200505-1200 // NVD: CVE-2005-1255

CREDITS

Sebastian Apelt

Trust: 0.6

sources: CNNVD: CNNVD-200505-1200

SOURCES

db:VULHUBid:VHN-12464
db:BIDid:13727
db:PACKETSTORMid:39312
db:CNNVDid:CNNVD-200505-1200
db:NVDid:CVE-2005-1255

LAST UPDATE DATE

2024-08-14T14:22:56.471000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-12464date:2008-11-15T00:00:00
db:BIDid:13727date:2007-04-03T03:12:00
db:CNNVDid:CNNVD-200505-1200date:2006-08-30T00:00:00
db:NVDid:CVE-2005-1255date:2008-11-15T05:46:12.157

SOURCES RELEASE DATE

db:VULHUBid:VHN-12464date:2005-05-25T00:00:00
db:BIDid:13727date:2005-05-24T00:00:00
db:PACKETSTORMid:39312date:2005-08-14T20:32:32
db:CNNVDid:CNNVD-200505-1200date:2005-05-25T00:00:00
db:NVDid:CVE-2005-1255date:2005-05-25T04:00:00