True North Software IA EMailServer Remote Format String Vulnerability
BID:14065
Info
True North Software IA EMailServer Remote Format String Vulnerability
| Bugtraq ID: | 14065 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2005 12:00AM |
| Updated: | Jun 27 2005 12:00AM |
| Credit: | Discovery of this issue is credited to Reed Arvin <[email protected]>. |
| Vulnerable: |
True North Software IA eMailServer Corporate Edition 5.2.2 Build: 1051 |
| Not Vulnerable: |
True North Software IA eMailServer Corporate Edition 5.3.4 Build: 2019 |
Discussion
True North Software IA EMailServer Remote Format String Vulnerability
True North Software IA eMailServer is prone to a remote format string vulnerability. This issue is likely due to a failure of the application to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
Reports indicate that immediate consequences of successful exploitation is a denial of service.
IA eMailServer version 5.2.2. Build: 1051, is prone to this issue. Previous versions might also be affected.
True North Software IA eMailServer is prone to a remote format string vulnerability. This issue is likely due to a failure of the application to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
Reports indicate that immediate consequences of successful exploitation is a denial of service.
IA eMailServer version 5.2.2. Build: 1051, is prone to this issue. Previous versions might also be affected.
Exploit / POC
True North Software IA EMailServer Remote Format String Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
True North Software IA EMailServer Remote Format String Vulnerability
Solution:
It is reported that the vendor has released version 5.3.4. Build: 2019 of the product to address this issue, however this is not confirmed. Please contact the vendor for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that the vendor has released version 5.3.4. Build: 2019 of the product to address this issue, however this is not confirmed. Please contact the vendor for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
True North Software IA EMailServer Remote Format String Vulnerability
References:
References:
- True North Software Homepage (True North Software)
- Denial of Service Vulnerability in True North Software, Inc. IA eMailServer Corp (Reed Arvin
)