PT-2003-2129 · Mercury · Mercur Mailserver

Published

2003-12-31

·

Updated

2017-07-11

·

CVE-2003-1177

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MERCUR Mailserver version 4.2 before SP3a
Description A buffer overflow issue exists in the base64 decoder of the affected software, potentially allowing remote attackers to cause a denial of service or execute arbitrary code. This can be achieved by sending a long AUTH command to the POP3 server or a long AUTHENTICATE command to the IMAP server.
Recommendations For MERCUR Mailserver version 4.2 before SP3a, update to a version that includes SP3a or later to resolve the issue. As a temporary workaround, consider restricting access to the POP3 and IMAP servers until the update can be applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1177

Affected Products

Mercur Mailserver