Floosietek FTGatePRO and FTGateOffice are high performance, feature rich mail servers for the Microsoft Windows operating system. The APOP command is used to provide secure authentication to a POP3 mail server. If an extremely long parameter is supplied to this command, it is possible to overflow memory allocated on the heap. Exploitation of this vulnerability may result in the execution of arbitrary code as the FTGate server process.
Floosietek FTGatePRO and FTGateOffice are high performance, feature rich mail servers for the Microsoft Windows operating system. The APOP command is used to provide secure authentication to a POP3 mail server. If an extremely long parameter is supplied to this command, it is possible to overflow memory allocated on the heap. Exploitation of this vulnerability may result in the execution of arbitrary code as the FTGate server process.