Spamguard Multiple Buffer Overflow Vulnerabilities
BID:10434
Info
Spamguard Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 10434 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 29 2004 12:00AM |
| Updated: | May 29 2004 12:00AM |
| Credit: | Discovery is credited to the vendor. |
| Vulnerable: |
Enderunix Spamguard 1.6 |
| Not Vulnerable: |
Enderunix Spamguard 1.7 -BETA |
Discussion
Spamguard Multiple Buffer Overflow Vulnerabilities
Spamguard is prone to multiple buffer overflow vulnerabilities that span various source files and functions. Some of the vulnerabilities are remotely exploitable and may permit execution of arbitrary code in the context of the process. Others are local in nature, but as the software is not typically installed setuid/setgid, should not present any security risk.
Spamguard is prone to multiple buffer overflow vulnerabilities that span various source files and functions. Some of the vulnerabilities are remotely exploitable and may permit execution of arbitrary code in the context of the process. Others are local in nature, but as the software is not typically installed setuid/setgid, should not present any security risk.
Exploit / POC
Spamguard Multiple Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Spamguard Multiple Buffer Overflow Vulnerabilities
Solution:
This issue has been addressed in Spamguard 1.7-BETA.
Enderunix Spamguard 1.6
Solution:
This issue has been addressed in Spamguard 1.7-BETA.
Enderunix Spamguard 1.6
-
Enderunix spamguard-1.7-BETA.tar.gz
http://www.enderunix.org/spamguard/spamguard-1.7-BETA.tar.gz
References
Spamguard Multiple Buffer Overflow Vulnerabilities
References:
References:
- Spamguard Homepage (Enderunix)
- EnderUNIX Security Anouncement (Isoqlog and Spamguard) (Murat Balaban
)