J-Security Center

Title: Floosietek FTGate IMAP Server Buffer Overflow Vulnerability

Severity: CRITICAL

Description:

FTGate is a family of email server software supporting such features as webmail, anti-virus and even dial up networking. The software is commercially available for the Microsoft Windows platform.

FTGate is prone to a remotely exploitable buffer overflow vulnerability in the IMAP server. Sending excessive data to the IMAP server on TCP port 143 can cause an internal buffer to be overrun, resulting in a failure of the service or potential arbitrary code execution. Code execution would occur with SYSTEM privileges.

This issue exists in various IMAP commands such as 'EXAMINE'.

Attackers require valid login credentials to exploit this vulnerability.

Affected Products:

  • Floosietek FTGate 4.0.0
  • Floosietek FTGate 4.1.0
  • Floosietek FTGate 4.4.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.