Netscape Messaging Server IMAP LIST Command Remote Overflow

critical Nessus Plugin ID 10580

Synopsis

The remote service is vulnerable to a buffer overflow.

Description

There is a buffer overflow in the remote imap server which allows an authenticated user to obtain a remote shell. A way to reproduce the overflow is to issue the command :

list AAAAA...AAAA /

Solution

Upgrade your imap server or use another one.

See Also

https://seclists.org/bugtraq/2000/Sep/471

Plugin Details

Severity: Critical

ID: 10580

File Name: netscape_imap_overflow.nasl

Version: 1.24

Type: remote

Published: 12/19/2000

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:netscape:messaging_server, cpe:/a:netscape:netscape_messaging_server_multiplexor

Required KB Items: imap/login, imap/password

Excluded KB Items: imap/false_imap

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/26/2000

Reference Information

CVE: CVE-2000-0961

BID: 1721