Short Name |
POP3:OVERFLOW:COMMAND |
---|---|
Severity |
High |
Recommended |
No |
Category |
POP3 |
Release Date |
2003/08/27 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This protocol anomaly triggers when it detects a POP3 command that exceeds four (4) bytes, the standard length for a POP3 command. This can indicate a non-standard POP3 client/server or an attacker has gained command-line access to the server.
Receiving such a message may indicate a buffer overflow attack attempt. The impact of the flaw depends on how a vulnerable POP3 server handles such a malformed message.