1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Eudora Internet Mail Server NTLM Authentication Denial of Service

Report ID: SA18356
Source: Secunia
Date of Discovery: 09.01.2006
Criticality: Moderate
Affects:
Eudora Internet Mail Server (EIMS) 3.x

Compromise From: From remote
Compromise Type: DoS

Summary

A vulnerability has been reported in Eudora Internet Mail Server (EIMS), which potentially can be exploited by malicious people to cause a DoS (Denial of Service).

Detailed Description

A vulnerability has been reported in Eudora Internet Mail Server (EIMS), which potentially can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability in caused due to an error in the handling of malformed NTLM authentication requests. This can be exploited to crash the server.

The vulnerability has been reported in versions prior to 3.2.8.

Note: It has also been reported that a corrupted Incoming Mail X or Temporary Mail file can also cause the server to crash.

Solution

Update to version 3.2.8.

-- EIMS 3.2 OS X --

EIMS Server X patch (requires version 3.2.7):
http://www.eudora.co.nz/EIMSServerX328patch.zip

EIMS Server Light X (requires version 3.2.6):
http://www.eudora.co.nz/EIMSServerLightX328patch.zip

-- EIMS 3.2 OS 7/8/9 --

EIMS Server X patch (requires version 3.2.7):
http://www.eudora.co.nz/EIMSServer327to328patch.sit

EIMS Server Light X (requires version 3.2.7):
http://www.eudora.co.nz/EIMSServerLight328patch.sit

CVE Reference

CVE-2006-0141