Re: [Full-disclosure] iDEFENSE Security Advisory 12.06.05: Ipswitch Collaboration Suite SMTP Format String Vulnerability

Owen Dhu <[email protected]> Tue, 13 Dec 2005 10:07:03 -0600
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <f54c85b40512130807n7b88a0a8na9935720b5abfa09__48969.1854724244$1134491837$gmane$org@mail.gmail.com>
On 12/6/05, [email protected] <[email protected]> wrote:

> Ipswitch Collaboration Suite SMTP Format String Vulnerability
[...]
> Remote exploitation of a format string vulnerability in Ipswitch
> IMail allows remote attackers to execute arbitrary code.

Can iDEFENSE (or anyone else) elaborate on this? I have been working with
this for a little while and iMail doesn't seem to be exploitable in this wa=
y.

TIA.