Description: Secunia research has discovered a vulnerability in Novell NetMail, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a boundary error in the NMAP (Network Messaging Application Protocol) Agent when handling an overly long user name in the "USER" command. This can be exploited to cause a stack-based buffer overflow and allows arbitrary code execution.
Successful exploitation requires valid logon to the NMAP Agent (e.g. if the default NMAP authentication credential has not been changed).
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.