Site Archives MDaemon

MDaemon WorldClient Vulnerability

Posted on November 19th, 2008

GSA Reference Number: AD081119-01
Updated: 11-19-2008

Simply Put: Secunia is reporting a vulnerability in MDaemon’s WorldClient webmail frontend.  Attackers could send a specially-crafted email that, if viewed in the WorldClient webmail interface, could run malicious scripts or HTML code on the user’s machine without their interaction.  All the user would have to do is read the email.  The vendor has a patch available.

MDaemon IMAP Advisory

Posted on March 17th, 2008

GSA Reference Number: AD080317-01

Simply Put: Alt-N MDaemon’s IMAP Server is vulnerable to a remote buffer overflow. The IMAP server’s FETCH command does not perform boundary checking on user input. Successful exploitation could result in compromise of the affected system.