|
Tumbleweed Integrated Messaging Exchange (IME) Server is prone to an input validation weakness that may allow a remote authenticated user to crash the IME Server as well as the Microsoft IIS server. Such an attack would require an administrator to restart the services as the watchdog IIS process is unable to gracefully restart the server. The /ime facility in Tumbleweed Integrated Messaging Exchange (IME) does not properly handle malformed input. The fprintf function in the TW_TxnAccMaillistEditEntryStart.tpl script, as reached by the 'lii' variable can be used in a crafted request to cause the IIS Admin Service Helper (inetinfo.exe) to crash.
|