Dr. Web Unspecified Buffer Overflow Vulnerability
BID:10628
Info
Dr. Web Unspecified Buffer Overflow Vulnerability
| Bugtraq ID: | 10628 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Jun 29 2004 12:00AM |
| Updated: | Jun 29 2004 12:00AM |
| Credit: | pheonix <[email protected]> reported this issue to Bugtraq. |
| Vulnerable: |
Dr.Web Dr.Web 4.31.4 Dr.Web Dr.Web |
| Not Vulnerable: | |
Discussion
Dr. Web Unspecified Buffer Overflow Vulnerability
It has been reported that an unspecified buffer overflow vulnerability exists in Dr. Web.
Users of Dr. Web have reported seeing this message logged to syslog by ProPolice on OpenBSD computers:
drwebd: stack overflow in function int scanMail(int, time_t *, int, int, const char *)
An unspecified buffer overflow in the scanMail() function may be exploitable. If it is, attempts to exploit it may result in the affected application crashing. This may also be leveraged to execute arbitrary code in the context of the Dr. Web process.
As more information is known, this BID will be updated.
It has been reported that an unspecified buffer overflow vulnerability exists in Dr. Web.
Users of Dr. Web have reported seeing this message logged to syslog by ProPolice on OpenBSD computers:
drwebd: stack overflow in function int scanMail(int, time_t *, int, int, const char *)
An unspecified buffer overflow in the scanMail() function may be exploitable. If it is, attempts to exploit it may result in the affected application crashing. This may also be leveraged to execute arbitrary code in the context of the Dr. Web process.
As more information is known, this BID will be updated.
Exploit / POC
Dr. Web Unspecified Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Dr. Web Unspecified Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.