Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

IMAP:AUTH-OF

Severity

High

Recommended

No

Recommended Action

Drop

Category

IMAP

Keywords

Authentication Overflow

Release Date

2005/04/15

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

IMAP: Authentication Overflow


This signature detects attempts to send overly long authorization commands to an IMAP server. Attackers can use this exploit remotely to attack vulnerable IMAP servers, such as MailEnable.

Extended Description

Cyrus IMAPD is a freely available, open source Interactive Mail Access Protocol (IMAP) daemon. It is available for Unix and Linux operating systems. It has been reported that Cyrus IMAPD does not sufficiently handle overly long strings. In some cases, when a user connects to the daemon, and upon negotiating the connection sends a login string of excessive length, a buffer overflow occurs. This could result in heap corruption and arbitrary words in memory being overwritten. It may be possible to exploit this issue to execute arbitrary code.

Affected Products

  • Carnegie Mellon University Cyrus IMAP Server 1.4.0
  • Carnegie Mellon University Cyrus IMAP Server 1.5.19
  • Carnegie Mellon University Cyrus IMAP Server 2.0.12
  • Carnegie Mellon University Cyrus IMAP Server 2.0.16
  • Carnegie Mellon University Cyrus IMAP Server 2.1.10
  • Carnegie Mellon University Cyrus IMAP Server 2.1.9

References

  • BugTraq: 6298
  • CVE: CVE-2002-1580

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out