Bugtraq mailing list archives

MDaemon Mail Server DoS - FIXED


From: Arvel () ALTN COM (Arvel Hathcock)
Date: Thu, 25 May 2000 13:49:42 -0500


Deerfield Communications (the Wingate perpetrators) MDaemon POP
server is vulnerable to bigass usernames causing a DoS.  MDaemon is a
mail server package for 95,98,NT and Win2k.  Many systems that run
Deerfield's World Client web-mail also use MDaemon.

Exploit tested on Win2kpro running MDaemon 3.0.3

Thanks for pointing this out.  We have since fixed this problem in our
mail server.  There are patches and new complete installation archives
which address this problem here:

ftp://ftp.altn.com/MDaemon/Release/

Thanks again!

Arvel Hathcock - CEO Alt-N Technologies
=======================================
MDaemon - http://www.mdaemon.com
RelayFax - http://www.relayfax.com
WorldClient - http://www.worldclient.com
========================================


Current thread: