[] NeoSense

Alt-N MDaemon 3.5.6/5.0.7/6.x - IMAP Denial of Service

Author: nitr0s
type: dos
platform: windows
port: 
date_added: 2001-03-23 
date_updated: 2012-08-20 
verified: 1 
codes: CVE-2001-0584;OSVDB-12045 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/2508/info

A successfully logged-in user, via IMAP, could cause MDaemon to terminate the connection. If the user submits either a 'SELECT' or 'EXAMINE' command appended with 250 or more characters, MDaemon will refuse any new connections to the IMAP service. A restart of the service is required in order to gain normal functionality.

* OK company.mail IMAP4rev1 MDaemon 3.5.6 ready

1 LOGIN JOE PASSWORD
* OK LOGIN completed
1 SELECT AAAAAAA....