ORF反垃圾邮件系统

邮件服务器-邮件系统-邮件技术论坛(BBS)

 找回密码
 会员注册
查看: 5331|回复: 1
打印 上一主题 下一主题

pop3 (110/tcp) 安全漏洞

[复制链接]
跳转到指定楼层
顶楼
发表于 2004-12-20 11:20:03 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
那位大哥有没有漏洞补丁亚~!<br>
<br>
<br>
The remote POP3 server might be vulnerable to a buffer overflow <br>
bug when it is issued at least one of these commands, with a too long <br>
argument :<br>
<br>
auth<br>
user<br>
pass<br>
<br>
If confirmed, this problem might allow an attacker to execute<br>
arbitrary code on the remote system, thus giving him an interactive<br>
session on this host.<br>
<br>
Solution : If you do not use POP3, disable this service in /etc/inetd.conf<br>
and restart the inetd process. Otherwise, upgrade to a newer version.<br>
<br>
See also : <a target=_blank href=http://online.securityfocus.com/archive/1/27197>http://online.securityfocus.com/archive/1/27197</a><br>
Risk factor : High<br>
CVE_ID : CAN-2002-0799, CVE-1999-0822<br>
BUGTRAQ_ID : 789, 790, 830, 894, 942, 1965, 2781, 2811, 4055, 4295, 4614<br>
NESSUS_ID : 10184
沙发
发表于 2004-12-20 22:05:35 | 只看该作者

re:问题:楼上所提及的pop3 (110...

问题:<br>
楼上所提及的pop3 (110/tcp) 安全漏洞<br>
解决办法是:If you do not use POP3, disable this service in /etc/inetd.conf and restart the inetd process. Otherwise, upgrade to a newer version (/etc/inetd.conf 以及INETD 这些是在LINUX OS里面存在)<br>
<br>
而帖子中的链接地址 <a target=_blank href=http://online.securityfocus.com/archive/1/27197>http://online.securityfocus.com/archive/1/27197</a><br>
简单看了下(俺英文不是很好)<br>
好像提到的又是另外一个含义(大意是使用在WINDOWS操作平台上的一些邮件系统存在漏洞)<br>
<br>
Many kind of POP3/SMTP server softwares for Windows have buffer overflow bug(by The Shadow Penguin Securuty <a target=_blank href=http://shadowpenguin.backsection.net)>http://shadowpenguin.backsection.net)</a><br>
<br>
1. Introduction<br>
<br>
I confirmed many kind of POP3/SMTP servers for Windows which are<br>published on "SOFT-SEEK.com" contain the buffer overflow bugs. I list the softwares which have buffer overflow bug, I also publish the exploit programs for some software.<br>
<br>
2. POP3/SMTP server softwares which have buffer overflow bugs<br>
<br>
Software Version Service Overflow Point<br>
-------------------------------------------------------<br>
@Work SmartServer3 3.51 SMTP long MAIL FROM:<br>
CMail Server 2.3 SP2 SMTP long MAIL FROM:<br>
Personal Mail Server 3.09 SMTP long MAIL FROM: (I've notified to developer)<br>
Tiny FTP daemon 0.51 POP3 long USER (I've notified, Now fixed)<br>
Internet Anywhere 2.2.2 POP3 long USER<br>
FuseMail 2.7 POP3 long USER,PASS<br>
aVirt Mail Server 3.3 POP/SMTP long MAIL FROM:,long USER<br>
<br>
WINWEBMAIL是否published on "SOFT-SEEK.com" 我就不太清楚了<br>
您需要登录后才可以回帖 登录 | 会员注册

本版积分规则

小黑屋|手机版|Archiver|邮件技术资讯网

GMT+8, 2026-8-4 22:49

Powered by Discuz! X3.2

© 2001-2016 Comsenz Inc.

本论坛为非盈利中立机构,所有言论属发表者个人意见,不代表本论坛立场。内容所涉及版权和法律相关事宜请参考各自所有者的条款。
如认定侵犯了您权利,请联系我们。本论坛原创内容请联系后再行转载并务必保留我站信息。此声明修改不另行通知,保留最终解释权。
*本论坛会员专属QQ群:邮件技术资讯网会员QQ群
*本论坛会员备用QQ群:邮件技术资讯网备用群

快速回复 返回顶部 返回列表