Bugtraq mailing list archives

Re: Infinite InterChange DoS


From: SNS Research <vuln-dev () greyhack com>
Date: Sat, 23 Dec 2000 00:05:52 +0100

An much easily way, if you have account to the system, is to send email with
very long subject string.

I did not have time to check if this also caused the same bug or not.
Anyway, this buy is discovered one years ago and Infinite fixed it within
three day after my report by version 3.61.

We tested this particular one against 3.61, which was found
vulnerable. The nature is probably the same though. We'd like to note
that we've received a reply from the vendor confirming this issue now.
A fix will be made availble from the vendor's website
http://www.infinte.com / http://www.ihub.com soon.

Happy holidays to all of you, have a safe new year :P

Scsi-bear
SNS Research


Current thread: