Vulnerabilities > CVE-2007-1578 - Unspecified vulnerability in Atrium Software Mercur Imapd 5.00.14
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Mercur IMAPD 5.00.14 Remote Denial of Service Exploit (win32). CVE-2007-1578. Dos exploit for windows platform |
file | exploits/windows_x86/dos/3527.pl |
id | EDB-ID:3527 |
last seen | 2016-01-31 |
modified | 2007-03-20 |
platform | windows_x86 |
port | |
published | 2007-03-20 |
reporter | mu-b |
source | https://www.exploit-db.com/download/3527/ |
title | Mercur IMAPD 5.00.14 - Remote Denial of Service Exploit Win32 |
type | dos |
Nessus
NASL family | Gain a shell remotely |
NASL id | MERCUR_IMAP_NTLM_OVERFLOW.NASL |
description | The remote host is running MERCUR Messaging, a commercial mail server for Windows. The IMAP server component of MERCUR Messaging is affected by a buffer overflow vulnerability involving its support for NTLM authentication. An unauthenticated, remote attacker can leverage this issue to crash the IMAP service or execute arbitrary code remotely. Note that MERCUR Messaging |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25118 |
published | 2007-04-30 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25118 |
title | MERCUR Messaging IMAP Server NTLM Authentication NTLMSSP Argument Remote Overflow |
code |
|
Saint
bid | 23058 |
description | MERCUR imapd NTLMSSP |
id | mail_imap_mercur |
osvdb | 33545 |
title | mercur_imap_ntlmssp |
type | remote |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0280.html
- http://www.digit-labs.org/files/exploits/mercur-v1.pl
- http://www.securityfocus.com/bid/23058
- http://securitytracker.com/id?1017798
- http://secunia.com/advisories/24596
- http://www.osvdb.org/33545
- http://www.vupen.com/english/advisories/2007/1053
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33120
- https://www.exploit-db.com/exploits/3527