First published: Wed Dec 31 2003(Updated: )
Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mercury Mail Server | =4.1 | |
Mercury Mail Server | =4.1_sp1 | |
Mercury Mail Server | =3.3 | |
Mercury Mail Server | =4.2_sp2 | |
Mercury Mail Server | =4.2_sp1 | |
Mercury Mail Server | =3.3_sp1 | |
Mercury Mail Server | =4.2 | |
Mercury Mail Server | =3.3_sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1177 has a severity level that can lead to a denial of service and potential arbitrary code execution.
To fix CVE-2003-1177, upgrade to MERCUR Mailserver version 4.2 SP3a or later.
CVE-2003-1177 affects MERCUR Mailserver versions 4.1, 4.1 SP1, 4.2 SP1, 4.2 SP2, 4.2, 3.3, 3.3 SP1, and 3.3 SP2.
Yes, CVE-2003-1177 can be exploited remotely through malicious AUTH commands to the POP3 or IMAP servers.
CVE-2003-1177 can lead to a denial of service, disrupting mail services, and possibly allowing attackers to execute arbitrary code.