Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v8 - Exploits Update (Fri Feb 13 2009)

Mercury SMTPD CRAM-MD5 Pre-Auth Buffer Overflow Exploit Update

Exploits/Remote  [Windows]




• Fri Feb 13 2009
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Mercury Mail Transport System. The vulnerability is caused due to a boundary error within Mercury/32 SMTP Server Module (mercurys.dll) when processing arguments to the AUTH CRAM-MD5 command. This can be exploited to cause a stack-based buffer overflow via an overly long, specially-crafted argument passed to the affected command. This update adds support for DEP (Data Execution Prevention).

Exploits Vulnerabiltiy: CVE-2007-4440



< Back to Product Updates