what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

smartserver3.remote.txt

smartserver3.remote.txt
Posted Nov 12, 1999
Authored by Andrew Reiter | Site bindview.com

There is a buffer overflow in NetCPlus' SmartServer3 POP3 server which can allow a remote attacker to execute arbitrary code on the machine. Affected are windows 95/98/NT machines running NetCPlus' SmartServer3 program with the POP3 server started. The version tested was 3.51.1.

tags | exploit, remote, overflow, arbitrary
systems | windows
SHA-256 | 33c1d77e009be8792bfdf0e14f137ed0d95f798035b257ffb85809fe276c7cff

smartserver3.remote.txt

Change Mirror Download
BindView Security Advisory


SmartServer3 Remote Buffer Overflow Technical Advisory

Issue date: 11/11/99
Contact: Andrew Reiter <areiter@bos.bindview.com>


Topic
-----

There is a buffer overflow in NetCPlus' SmartServer3 POP3 server which can
allow a remote attacker to execute arbitrary code on the machine.


Affected Systems
----------------

Windows 95/98/NT machines running NetCPlus' SmartServer3 program with
the POP3 server started. The version tested was 3.51.1 (built on 7/12/99).


Overview
--------

NetCPlus is the maker of low-cost business email solutions such as
SmartServer3, BrowseGate, and MailTreeve. SmartServer3 is a product that
contains SMTP and POP3 servers. The POP3 server, however, has a security
vulnerability in the form of a buffer overflow. If one sends a large string
(~1000 characters) to the POP3 server, the server replies with "-ERR non-
existant command" (sic) and the POP3 server stops running. This causes a
page fault in KERNEL32.DLL, but does not appear to be exploitable. However,
when the string "USER <~800 char's>\r\n\r\n" is sent, a fault is caused in
NCPOPSERV.EXE. This can be exploited to allow a remote attacker to execute
arbitrary code on the victim server.


Impact
------

Remote users can exploit a buffer overflow and execute commands on the
POP3 server's machine.


Appendix A, Software Information
--------------------------------

NetCPlus Internet Solutions, Ltd.
www.netcplus.com
www.netcplus.co.uk

NetCPlus is soon releasing SmartServer3 version 3.60 which fixes this
security flaw.



http://www.bindview.com/security
--

Login or Register to add favorites

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    17 Files
  • 8
    Oct 8th
    66 Files
  • 9
    Oct 9th
    25 Files
  • 10
    Oct 10th
    20 Files
  • 11
    Oct 11th
    21 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    14 Files
  • 15
    Oct 15th
    49 Files
  • 16
    Oct 16th
    28 Files
  • 17
    Oct 17th
    23 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close