Executive brief
Eudora Internet Mail Server (EIMS) is an email server application for older MacOS systems. A vulnerability allows a remote attacker to crash the mail service by sending a specially crafted, overly long command. In some cases, this can cause the entire computer to stop responding, requiring a manual restart and disrupting email communications.
Technical details
A buffer overflow vulnerability exists in the Eudora Internet Mail Server (EIMS) versions 2.01 and earlier running on MacOS. The flaw is triggered when the server receives an excessively long string (approximately 1000+ characters) via the USER command on port 106 (typically used for password changes or account management). A remote, unauthenticated attacker can exploit this to crash the EIMS service. In certain instances, the overflow can lead to a kernel-level failure, resulting in a complete system hang or crash of the host MacOS machine.
Affected products
- Qualcomm Eudora Internet Mail Server (EIMS) 2.01 and earlier
Timeline
- 1998-04-14: disclosed: Initial disclosure on Bugtraq mailing list
- 1998-04-14: advisory: NVD publication date