Vulnerabilities > CVE-2003-1177 - Unspecified vulnerability in Atrium Software Mercur Mailserver
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server.
Vulnerable Configurations
Exploit-Db
description | Atrium Software Mercur Mailserver 3.3/4.0/4.2 IMAP AUTH Remote Buffer Overflow Vulnerability. CVE-2003-1177. Dos exploit for windows platform |
id | EDB-ID:23267 |
last seen | 2016-02-02 |
modified | 2003-10-20 |
published | 2003-10-20 |
reporter | Kostya KORTCHINSKY |
source | https://www.exploit-db.com/download/23267/ |
title | Atrium Software Mercur Mailserver 3.3/4.0/4.2 IMAP AUTH Remote Buffer Overflow Vulnerability |
Nessus
NASL family | Windows |
NASL id | MERCUR_AUTH_OVERFLOW.NASL |
description | The remote Atrium MERCUR SMTP server (mail server) seems to be vulnerable to a remote buffer overflow. Successful exploitation of this vulnerability would give a remote attacker administrative access to the mail server and access to potentially confidential data. The IMAP and POP3 servers are affected by similar issues involving the AUTHENTICATE and AUTH commands respectively. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11910 |
published | 2003-10-27 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11910 |
title | MERCUR Mailserver SMTP / IMAP / POP3 Servers Remote Overflows |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2003-q4/1459.html
- http://www.securiteam.com/windowsntfocus/6U00N1P8KC.html
- http://www.securityfocus.com/bid/8861
- http://www.securityfocus.com/bid/8889
- http://www.osvdb.org/2688
- http://secunia.com/advisories/10038
- http://www.atrium-software.com/mail%20server/pub/mcr42sp3a.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13468