Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-0447
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-0447

Description:
Multiple buffer overflows in E-Post Mail Server 4.10 and SPA-PRO Mail @Solomon 4.00 allow remote attackers to execute arbitrary code via a long username to the (1) AUTH PLAIN or (2) AUTH LOGIN SMTP commands, which is not properly handled by (a) EPSTRS.EXE or (b) SPA-RS.EXE; (3) a long username in the APOP POP3 command, which is not properly handled by (c) EPSTPOP4S.EXE or (d) SPA-POP3S.EXE; (4) a long IMAP DELETE command, which is not properly handled by (e) EPSTIMAP4S.EXE or (f) SPA-IMAP4S.EXE.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/24333
  http://xforce.iss.net/xforce/xfdb/24334
  http://xforce.iss.net/xforce/xfdb/24331

SAID
  Secunia Advisory: SA18480

OSVDB
  22762
  22763
  22761

MISC
  http://secunia.com/secunia_research/2006-1/advisory/

BID
  16379


Return to the previous page.