8.05 Hotfix 2 Details:
- Corrects a peering problem and an issue with long host names in the Queue
Manager.
- Fixes a possible LDAP Denial of Service vulnerability
- Includes 8.05 Hotfix 1 updates

Bill
----- Original Message ----- 
From: "Joshua Levitsky" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, February 17, 2004 7:23 PM
Subject: [IMail Forum] Fw: [Full-Disclosure] iDEFENSE Security Advisory
02.17.04: Ipswitch IMail LDAP Daemon Remote Buffer Overflow


> ----- Original Message ----- 
> From: "iDefense Labs" <[EMAIL PROTECTED]>
> To: "[EMAIL PROTECTED]"
<'[EMAIL PROTECTED]'>;
> <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]>;
> <[EMAIL PROTECTED]>; "[EMAIL PROTECTED]" <'[EMAIL PROTECTED]'>
> Sent: Tuesday, February 17, 2004 4:21 PM
> Subject: [Full-Disclosure] iDEFENSE Security Advisory 02.17.04: Ipswitch
> IMail LDAP Daemon Remote Buffer Overflow
>
>
> > iDEFENSE Security Advisory 02.17.04
> >
> > Ipswitch IMail LDAP Daemon Remote Buffer Overflow
> > http://www.idefense.com/application/poi/display?id=74
> > February 17, 2004
> >
> > I. BACKGROUND
> >
> > Ipswitch IMail server is a Windows based messaging solution with a
> > customer base of over 53 million users. More information about the
> > application is available at
> > http://www.ipswitch.com/products/IMail_Server/index.html.
> >
> > II. DESCRIPTION
> >
> > Exploitation of a remote buffer overflow within the LDAP daemon of
> > Ipswitch IMAIL Server allows attackers to execute arbitrary code under
> > administrator privileges. LDAP messages are comprised of various tags
> > consisting of an identifier, a length and the content. An integer is
> > represented in LDAP by the identifier byte 0x02, followed by the length
> > of the integer in bytes. This is followed by the actual integer itself.
> > As an example the following tag: 0x02 0x03 0x0A 0x25 0xBD represents the
> > integer 665,501 (0xA25BD). The problem exists due to insufficient bounds
> > checking upon copying of user supplied data with large tag lengths to a
> > stack based buffer. The following assembly instruction can be abused to
> > overwrite memory addresses as offsets from the current frame pointer
> > because the attacker has control over ecx and var_4 at the time of
> > exploitation:
> >
> > .text:00401188 mov byte ptr [ebp+ecx+var_4], dl
> >
> > An attacker can utilize this to overwrite the address of the Global
> > Exception Handler, which can be found at a static distance from the
> > frame pointer. Overwriting this address with that of a memory location
> > containing a JMP/CALL ebx instruction (in Windows 2000)
> > or a POP xxx POP xxx RET instruction (in Windows XP), allows the
> > attacker to redirect the flow of control to his or her own supplied
> > code.
> >
> > III. ANALYSIS
> >
> > Successful exploitation allows unauthenticated remote attackers to
> > execute arbitrary code under administrator privileges. Exploitation is
> > possible across both Windows 2000 and XP platforms. However, it requires
> > minor changes in order to work.
> >
> > IV. DETECTION
> >
> > iDEFENSE has confirmed that the LDAP daemon (iLDAP.exe ver. 3.9.15.10)
> > shipping with IMail Server version 8.03 is vulnerable. It us suspected
> > that earlier versions are vulnerable as well.
> >
> > V. WORKAROUNDS
> >
> > Disable or firewall the LDAP service (TCP port 389) if unneeded.
> >
> > VI. RECOVERY
> >
> > Successful exploitation can cause the LDAP daemon to crash and will
> > require a restart in order to resume normal operation.
> >
> > VII. VENDOR RESPONSE
> >
> > "Testing has completed their review of 8.05 Hotfix 2 and we are ready to
> > release."
> >
> > The fix will be available for download at:
> >
> > http://www.ipswitch.com/support/imail/releases/imail_professional/im805H
> > F2.html
> >
> > VIII. CVE INFORMATION
> >
> > A Mitre Corp. Common Vulnerabilities and Exposures (CVE) number has not
> > been assigned yet.
> >
> > IX. DISCLOSURE TIMELINE
> >
> > October 31, 2003    Exploit acquired by iDEFENSE
> > February 2, 2004    Initial vendor notification
> > February 3, 2004    iDEFENSE clients notified
> > February 3, 2004    Vendor response received
> > February 17, 2004   Coordinated public disclosure
> >
> > _______________________________________________
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.netsys.com/full-disclosure-charter.html
> >
>
>
> To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
> List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
> Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
>


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to