Description: A vulnerability has been reported in IMail Server, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a boundary error in the SMTP service when processing certain strings. This can be exploited to cause a stack-based buffer overflow by supplying an overly long string containing "@" and ":" characters.
Successful exploitation allows execution of arbitrary code.
The vulnerability is reported in the following versions:
* Ipswitch Collaboration 2006 Suite Premium Edition
* Ipswitch Collaboration 2006 Suite Standard Edition
* Ipswitch Collaboration Suite 2.02
* IMail Server 8.22
* IMail Plus
* IMail Secure
Prior versions may also be affected.
Solution: Update to version 2006.1 or apply vendor patches.
Provided and/or discovered by: Discovered by an anonymous person and reported via ZDI.
Changelog: 2006-09-08: Added CVE reference and additional information from ZDI.
2006-11-06: Added other affected product versions and patch information.
2006-12-08: Added link to US-CERT.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.