The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS02-037: Server Response To SMTP Client EHLO Command Results In Buffer Overrun (Q326322)
Time: 00:00 EST/05:00 GMT | News Source: ActiveWin.com | Posted By: Robert Stein

The Internet Mail Connector (IMC) enables Microsoft Exchange Server to communicate with other mail servers via SMTP. When the IMC receives an SMTP extended Hello (EHLO) protocol command from a connecting SMTP server, it responds by sending a status reply that starts with the following: 250-Hello. A security vulnerability results because of an unchecked buffer in the IMC code that generates the response to the EHLO protocol command. If the total length of the message exceeds a particular value, the data would overrun the buffer. If the buffer were overrun with random data, it would result in the failure of the IMC. If, however, the buffer were overrun with carefully chosen data, it could be possible for the attacker to run code in the security context of the IMC, which runs as Exchange5.5 Service Account.

Write Comment
Return to News

  Displaying 301 through 302 of 302
Prev | First
  The time now is 10:48:30 PM ET.
Any comment problems? E-mail us
#301 By 4240821 (62.76.153.72) at 11/24/2024 5:26:46 PM
https://justpaste.me/CB2G1
https://justpaste.me/CCQM
https://justpaste.me/C4FG
https://justpaste.me/CFHE
https://justpaste.me/BgJZ3
https://justpaste.me/C2Zc1
https://justpaste.me/C7uW
https://justpaste.me/Be1j1
https://justpaste.me/CO1t1
https://justpaste.me/Bkvx

#302 By 4240821 (77.83.4.69) at 11/24/2024 9:19:22 PM
https://justpaste.me/CENs3
https://justpaste.me/CWnI
https://justpaste.me/CVjO
https://justpaste.me/CZtF2
https://justpaste.me/CIQT2
https://justpaste.me/CQC0
https://justpaste.me/CHiZ1
https://justpaste.me/CIFX2
https://justpaste.me/CMOK1
https://justpaste.me/Bgex5

Write Comment
Return to News
  Displaying 301 through 302 of 302
Prev | First
  The time now is 10:48:30 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *