Update Protection against Novell NetMail IMAP Verb Literal Buffer Overflow Vulnerability
| Check Point Reference: | CPAI-2007-049 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | FrSIRT/ADV-2006-5134 | |
| Industry Reference(s): | CVE-2006-6424 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Novell NetMail version 3.52 and prior | ||
| Vulnerability Description A buffer overflow vulnerability exists in Novell NetMail IMAP service. Novell NetMail is an electronic mail server product that supports various email access and exchange protocols, including the Internet Message Access Protocol (IMAP). IMAP is a standard protocol for accessing e-mail from a local server that provides management of received messages on a remote server. A remote attacker can exploit this issue to trigger a buffer overflow which may lead to an application crash and to arbitrary code execution. |
||
|
Update/Patch Available Apply patches: Novell NetMail 3.52e FTF 2 for NetWare : Novell NetMail 3.52e FTF 2 for Windows : Novell NetMail 3.52e FTF 2 for Linux : |
|
|
Vulnerability Details The vulnerability is due to a buffer overflow error when processing a malformed IMAP command that contains overly long verb literals. A remote attacker can exploit this flaw by appending verbs to an IMAP command to specify a command continuation request. Successful exploitation may allow an attacker to create a denial of service condition or execute arbitrary code on an affected system. |
Protection Overview
Malformed IMAP commands may cause a buffer overflow on an affected IMAP server. The protection addresses this issue by detecting and blocking malformed and long IMAP literals that exceed a certain length, except for the following IMAP commands: FETCH, UID and APPEND.
In order for the protection to be activated, update your VPN-1/InterSpect/Connectra product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
The Update released on April 15, 2007 includes the following protections:
Symantec Veritas NetBackup Code Execution Vulnerability (CPAI-2007-045)
Oracle ORADC ActiveX Control Code Execution Vulnerability (CPAI-2007-046)
Trend Micro ServerProtect Buffer Overflow Vulnerabilities (CPAI-2007-047)
Novell Netmail WebAdmin Buffer Overflow Vulnerability (CPAI-2007-048)
Novell NetMail IMAP Verb Literal Buffer Overflow Vulnerability (CPAI-2007-049)
Microsoft Windows Workstation Service Vulnerability (CPAI-2007-050)
Trend Micro OfficeScan ActiveX Buffer Overflow Vulnerability (CPAI-2007-051)
Protect Yourself against FTP Brute Force Attacks (SBP-2007-05)
Protect Yourself against FTP Format Strings Attacks (SBP-2007-06)