Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Nessus: users

Exchange XEXCH50 Remote Buffer Overflow

 

 

Nessus users RSS feed   Index | Next | Previous | View Threaded


gmtrillo at gmail

Dec 3, 2008, 6:36 PM

Post #1 of 2 (838 views)
Permalink
Exchange XEXCH50 Remote Buffer Overflow

Hello,
I would like to know why I am getting this vulnerability "Exchange XEXCH50
Remote Buffer Overflow" on a Windows Server 2003 and an Exchange Server
2003.

My understanding was that this vulnerability was applicable only to Exchange
Server 5.5 or 2000.

I will appreciate your help to this question.

Regards,
Guillermo


theall at tenablesecurity

Dec 4, 2008, 8:23 AM

Post #2 of 2 (772 views)
Permalink
Re: Exchange XEXCH50 Remote Buffer Overflow [In reply to]

On Dec 3, 2008, at 9:36 PM, Guillermo Trillo wrote:
> I would like to know why I am getting this vulnerability "Exchange
> XEXCH50 Remote Buffer Overflow" on a Windows Server 2003 and an
> Exchange Server 2003.
>
>
> My understanding was that this vulnerability was applicable only to
> Exchange Server 5.5 or 2000.

MS03-046 says that their patch now requires authenticated connections
between Exchange servers in order to use an extended SMTP command such
as XEXCH50, yet the plugin seems to have been able to use it without
supplying any credentials.

To better diagnose the issue then, would you mind re-running the
plugin and sending me privately the traffic from the Exchange
server(s) flagged as vulnerable? You can do this by setting "debug" to
1 in the plugin (eg, "debug=1;") and running the plugin from the
commandline using nasl or taking a packet capture while doing a scan.
Thanks in advance,

George
--
theall [at] tenablesecurity



_______________________________________________
Nessus mailing list
Nessus [at] list
http://mail.nessus.org/mailman/listinfo/nessus

Nessus users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.