SMTP.Proxy Remote Format String Vulnerability
BID:10509
Info
SMTP.Proxy Remote Format String Vulnerability
| Bugtraq ID: | 10509 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2004 12:00AM |
| Updated: | Jun 10 2004 12:00AM |
| Credit: | Discovery is credited to Joel Eriksson. |
| Vulnerable: |
smtp.proxy smtp.proxy 1.1.3 |
| Not Vulnerable: | |
Discussion
SMTP.Proxy Remote Format String Vulnerability
smtp.proxy is prone to a remotely exploitable format string vulnerability.
The vulnerability occurs in routines that log SMTP headers in email passed through the proxy. This issue may be exploited to execute arbitrary code.
smtp.proxy is prone to a remotely exploitable format string vulnerability.
The vulnerability occurs in routines that log SMTP headers in email passed through the proxy. This issue may be exploited to execute arbitrary code.
Exploit / POC
SMTP.Proxy Remote Format String Vulnerability
The researcher who discovered this vulnerability has developed exploit code that is not publicly available or known to be circulating in the wild.
The researcher who discovered this vulnerability has developed exploit code that is not publicly available or known to be circulating in the wild.
Solution / Fix
SMTP.Proxy Remote Format String Vulnerability
Solution:
This issue is reportedly addressed in smtp.proxy 1.3.3. This version does not appear to be publicly available at the time of writing. Users are advised to contact the vendor for further information about the availability of fixed versions.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
This issue is reportedly addressed in smtp.proxy 1.3.3. This version does not appear to be publicly available at the time of writing. Users are advised to contact the vendor for further information about the availability of fixed versions.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SMTP.Proxy Remote Format String Vulnerability
References:
References:
- 0xbadc0ded Advisory #04 - 2004/06/10 - smtp.proxy <= 1.1.3 (0xbadc0ded)
- smtp.proxy Homepage (smtp.proxy)