NakedSoft Gaucho POP3 Email Header Buffer Overflow Vulnerability
BID:11023
Info
NakedSoft Gaucho POP3 Email Header Buffer Overflow Vulnerability
| Bugtraq ID: | 11023 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2004 12:00AM |
| Updated: | Aug 24 2004 12:00AM |
| Credit: | Discovery of this issue is credited to Tan Chew Keong. |
| Vulnerable: |
NakedSoft Gaucho 1.4 build 145 |
| Not Vulnerable: |
NakedSoft Gaucho 1.4 build 151 |
Discussion
NakedSoft Gaucho POP3 Email Header Buffer Overflow Vulnerability
NakedSoft Gaucho is affected by an email header buffer overflow vulnerability. This issue is due to a failure of the application to properly validate user input string lengths before copying them to finite process buffers.
Ultimately a malicious attacker may exploit this issue to execute arbitrary code on the affected computer with the privileges of the user who started the affected application by sending a specially crafted malicious email.
NakedSoft Gaucho is affected by an email header buffer overflow vulnerability. This issue is due to a failure of the application to properly validate user input string lengths before copying them to finite process buffers.
Ultimately a malicious attacker may exploit this issue to execute arbitrary code on the affected computer with the privileges of the user who started the affected application by sending a specially crafted malicious email.
Exploit / POC
NakedSoft Gaucho POP3 Email Header Buffer Overflow Vulnerability
The following proof of concept exploit is available:
The following proof of concept exploit is available:
Solution / Fix
NakedSoft Gaucho POP3 Email Header Buffer Overflow Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue. Users are advised to upgrade at the first possible opportunity.
NakedSoft Gaucho 1.4 build 145
Solution:
The vendor has released an upgrade dealing with this issue. Users are advised to upgrade at the first possible opportunity.
NakedSoft Gaucho 1.4 build 145
-
NakedSoft Gaucho Version 1.4 build 151
http://homepage1.nifty.com/nakedsoft/Gaucho/G-14B151.zip
References
NakedSoft Gaucho POP3 Email Header Buffer Overflow Vulnerability
References:
References:
- Gaucho 1.4 Email Client has Buffer Overflow Vulnerability when Receiving Email (Tan Chew Keong)
- Project Home Page (Gaucho)