SPA-PRO Mail @Solomon IMAP Server Buffer Overflow Vulnerability
BID:13839
Info
SPA-PRO Mail @Solomon IMAP Server Buffer Overflow Vulnerability
| Bugtraq ID: | 13839 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2005 12:00AM |
| Updated: | Jun 02 2005 12:00AM |
| Credit: | Tan Chew Keong <[email protected]> is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
E-POST Inc. SPA-PRO Mail @Solomon 4.0 4 E-POST Inc. SPA-PRO Mail @Solomon 4.0 3 E-POST Inc. SPA-PRO Mail @Solomon 4.0 1 |
| Not Vulnerable: |
E-POST Inc. SPA-PRO Mail @Solomon 4.0 5 |
Discussion
SPA-PRO Mail @Solomon IMAP Server Buffer Overflow Vulnerability
SPA-PRO Mail @Solomon IMAP Server is susceptible to a remote buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.
Remote attackers may exploit this vulnerability to execute arbitrary executable machine code in the context of the affected application.
SPA-PRO Mail @Solomon IMAP Server is susceptible to a remote buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.
Remote attackers may exploit this vulnerability to execute arbitrary executable machine code in the context of the affected application.
Exploit / POC
SPA-PRO Mail @Solomon IMAP Server Buffer Overflow Vulnerability
A proof of concept exploit has been provided:
A proof of concept exploit has been provided:
Solution / Fix
SPA-PRO Mail @Solomon IMAP Server Buffer Overflow Vulnerability
Solution:
It is reported that the vendor has released version 4.05 of the affected package to address this issue. Users of affected packages should contact the vendor for further information on obtaining fixes.
Solution:
It is reported that the vendor has released version 4.05 of the affected package to address this issue. Users of affected packages should contact the vendor for further information on obtaining fixes.
References
SPA-PRO Mail @Solomon IMAP Server Buffer Overflow Vulnerability
References:
References:
- SPA-PRO Mail @Solomon (E-POST Inc.)
- SPA-PRO Mail @Solomon IMAP Server Directory Traversal and Buffer Overflow Vulner (SIG^2 Vulnerability Research)