QwikMail Remote Format String Vulnerability
BID:11572
Info
QwikMail Remote Format String Vulnerability
| Bugtraq ID: | 11572 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2004 12:00AM |
| Updated: | Nov 01 2004 12:00AM |
| Credit: | Dark Eagle <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Amir Malik QwikMail 0.3 |
| Not Vulnerable: | |
Discussion
QwikMail Remote Format String Vulnerability
It is reported that QwikMail is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
This vulnerability reportedly allows remote attackers to execute arbitrary code in the context of the affected daemon process.
Version 0.3 was reported susceptible to this vulnerability. Other versions may also be affected.
It is reported that QwikMail is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
This vulnerability reportedly allows remote attackers to execute arbitrary code in the context of the affected daemon process.
Version 0.3 was reported susceptible to this vulnerability. Other versions may also be affected.
Exploit / POC
QwikMail Remote Format String Vulnerability
The following exploit has been made available:
The following exploit has been made available:
Solution / Fix
QwikMail Remote Format String Vulnerability
Solution:
The vendor has provided a patch for version 0.3 of the affected package:
Amir Malik QwikMail 0.3
Solution:
The vendor has provided a patch for version 0.3 of the affected package:
Amir Malik QwikMail 0.3
-
Amir Malik qwik-smtpd-0.3.patch
http://qwikmail.sourceforge.net/smtpd/qwik-smtpd-0.3.patch
References
QwikMail Remote Format String Vulnerability
References:
References:
- qwik-smtpd format string vulnerability (unl0ck.info)
- QwikMail ChangeLog (Amir Malik)
- QwikMail Home Page (Amir Malik)