Bolthole Filter Address Parsing Buffer Overflow Vulnerability
BID:11977
Info
Bolthole Filter Address Parsing Buffer Overflow Vulnerability
| Bugtraq ID: | 11977 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Dec 15 2004 12:00AM |
| Credit: | Discovery is credited to Ariel Berkman. |
| Vulnerable: |
Bolthole Filter 2.6.1 |
| Not Vulnerable: | |
Discussion
Bolthole Filter Address Parsing Buffer Overflow Vulnerability
Bolthole Filter is prone to a buffer overflow vulnerability. This issue is exposed when the software parses email address data.
If successfully exploited, this vulnerability could result in execution of arbitrary code in the context of the process.
Bolthole Filter is prone to a buffer overflow vulnerability. This issue is exposed when the software parses email address data.
If successfully exploited, this vulnerability could result in execution of arbitrary code in the context of the process.
Exploit / POC
Bolthole Filter Address Parsing Buffer Overflow Vulnerability
The following example exploit has been published:
The following example exploit has been published:
Solution / Fix
Bolthole Filter Address Parsing Buffer Overflow Vulnerability
Solution:
The vendor has acknowledged this issue and will be addressing it with the pending release of Filter 2.6.2. The vendor has also made a patch available in the meantime.
Bolthole Filter 2.6.1
Solution:
The vendor has acknowledged this issue and will be addressing it with the pending release of Filter 2.6.2. The vendor has also made a patch available in the meantime.
Bolthole Filter 2.6.1
-
Bolthole filterpatch
http://www.securityfocus.com/data/vulnerabilities/downloads/filterpatc h
References
Bolthole Filter Address Parsing Buffer Overflow Vulnerability
References:
References:
- [remote] [control] elm/bolthole filter 2.6.1 save_embedded_address overflows add ("D. J. Bernstein"
) - Bolthole Filter Homepage (Bolthole)
- Re: [remote] [control] elm/bolthole filter 2.6.1 save_embedded_address overflows (Philip Brown
)