A remote overflow exists in IMail Server. The IMAP service (IMAP4D32.EXE) fails to perform proper bounds checking resulting in a buffer overflow. By passing an overly long string to the 'SELECT' command, a remote attacker can cause the IMAP service to crash resulting in a loss of availability.
Classification
Location:
Remote/Network Access Required
Attack Type:
Denial of Service
Impact:
Loss of Availability
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Technical
Valid login credentials are required to use the SELECT command.
Solution
Upgrade to version 8.2 Hotfix 2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.