Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gain root remotely >> MailEnable POP3 Server Authentication Vulnerabilities


Vulnerability Assessment Details

MailEnable POP3 Server Authentication Vulnerabilities

Vulnerability Assessment Summary
Tries to crash MailEnable POP3 Server

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote POP3 server is affected by two authentication issues.

Description :

The remote host is running MailEnable, a commercial mail server for
Windows.

The POP3 server bundled with the version of MailEnable on the remote
host has a buffer overflow flaw involving authentication commands that
can be exploited remotely by an unauthenticated attacker to crash the
affected service and possibly to execute code remotely.

In addition, it reportedly has a cryptographic implementation mistake
that weakens authentication security.

See also :

http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044229.html
http://www.mailenable.com/hotfix/default.asp

Solution :

Apply the ME-10011 hotfix or upgrade to MailEnable Standard Edition
1.93 / Professional Edition 1.73 / Enterprise Edition 1.21 or later

Network Security Threat Level:

High / CVSS Base Score : 7.0
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)

Networks Security ID: 17162

Vulnerability Assessment Copyright: This script is Copyright (C) 2006-2007 Tenable Network Security

Cables, Connectors


Vintage Apple Macintosh Computer Serial Mouse M0100 And A+Mouse picture

Vintage Apple Macintosh Computer Serial Mouse M0100 And A+Mouse

$80.00



Vintage Apple Macintosh Computer Serial Mouse M0100 picture

Vintage Apple Macintosh Computer Serial Mouse M0100

$45.00



Vintage Apple M9102LL/B Performa Plus Display Computer Monitor Screen picture

Vintage Apple M9102LL/B Performa Plus Display Computer Monitor Screen

$86.39



Vintage Apple Newton MessagePad 110 TESTED WORKS w Original Documents, VHS picture

Vintage Apple Newton MessagePad 110 TESTED WORKS w Original Documents, VHS

$80.00



VINTAGE APPLE MAC M0110A KEYBOARD W/ CABLE  picture

VINTAGE APPLE MAC M0110A KEYBOARD W/ CABLE

$89.89



Apple Vintage Apple Adjustable Keyboard w/Box M1242LL/A Mega Rare 1992 picture

Apple Vintage Apple Adjustable Keyboard w/Box M1242LL/A Mega Rare 1992

$199.99



Vintage Apple Logo Calculator. New in original box.  LAST ONE................... picture

Vintage Apple Logo Calculator. New in original box. LAST ONE...................

$18.55



Apple Computer Vintage sheet of 1990s rainbow logo stickers 2 Sticker Sheet picture

Apple Computer Vintage sheet of 1990s rainbow logo stickers 2 Sticker Sheet

$4.80



Vintage Apple Computer Monitor G090S A2M4090 w/ Stand - Tested picture

Vintage Apple Computer Monitor G090S A2M4090 w/ Stand - Tested

$179.99



Vintage Apple Pro Keyboard M7803 USB Wired Clear White TESTED  picture

Vintage Apple Pro Keyboard M7803 USB Wired Clear White TESTED

$27.99



Discussions

No Discussions have been posted on this vulnerability.