IMAP: Mercury Mail IMAP Command Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the Mercury Mail Server. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

Mercury Mail is reported susceptible to multiple stack-based buffer-overflow vulnerabilities in its IMAP server implementation. These issues are due to the application's failure to properly bounds-check user-supplied input before copying it to a finite-sized memory buffer. Exploiting these vulnerabilities allows authenticated, remote attackers to execute arbitrary machine code in the context of the affected server process. Versions prior to 4.01a of Mercury Mail are reported affected by these vulnerabilities; other versions may also be affected. Note: BID 11788 has been consolidated with this BID; they actually represent the same issues.

Affected Products

David_harris mercury_(win32_version)

References

BugTraq: 11775

CVE: CVE-2004-1211

Short Name
IMAP:OVERFLOW:MERCURY-MAIL-BO
Severity
Major
Recommended
False
Recommended Action
Drop
Category
IMAP
Keywords
Buffer CVE-2004-1211 Command IMAP Mail Mercury Overflow bid:11775
Release Date
06/19/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
Port
TCP/143
False Positive
Unknown
Vendors

David_harris

CVSS Score

10.0

Found a potential security threat?