Title: CMS Mail Server Buffer Overflow Vulnerabilities
Severity: CRITICAL
Description:
The CMS Mail Server is a SMTP mail server for Windows 95/98 and Windows NT. The program has a number of buffer overflows, at least two of which allow the remote execution of arbitrary code.
One overflows is in the handling of the HELO SMTP command. Another is in the handling of the MAIL FROM SMTP command. Neither of these seems to allow execution of arbitrary code.
Another overflow is in the handling of the VRFY command. When a long string without the '@' symblo is passed as an argument. This overflow can overwrite the return address and allow the execution of arbitrary code. A related overflow in the handling of the VRFY command occurs when the long contains the '@' symbol. This overflow seems not capable of executing arbitrary code.
The handling of the RCPT TO command also contains a similar overflow that allows the execution of arbitrary code.
All earlier version of CMS Mail possibly vulnerable as well.
Affected Products:
- Computer Software Manufaktur CSM Mail Server 1999.7.0.D
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.