SMTP: MailEnable NTLM Authentication Buffer Overflow

This signature detects attempts to exploit a known vulnerability in MailEnable's SMTP NTLM authentication. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

MailEnable is prone to multiple remote vulnerabilities. These issues arise in the SMTP server during NTLM authentication and may facilitate arbitrary code execution or denial-of-service conditions. MailEnable Professional 2.0 and MailEnable Enterprise 2.0 are reported vulnerable to these issues.

Affected Products

Mailenable mailenable_professional

References

BugTraq: 20290

CVE: CVE-2006-5176

Short Name
SMTP:OVERFLOW:NTLM-AUTH-OF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
SMTP
Keywords
Authentication Buffer CVE-2006-5176 CVE-2006-5177 MailEnable NTLM Overflow bid:20290
Release Date
09/27/2010
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Mailenable

CVSS Score

9.3

Found a potential security threat?