SoftiaCom WMailserver Remote Buffer Overflow Vulnerability
BID:14213
Info
SoftiaCom WMailserver Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 14213 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2005 12:00AM |
| Updated: | Feb 07 2006 08:55PM |
| Credit: | This issue was disclosed by fRoGGz <[email protected]>. |
| Vulnerable: |
SoftiaCom WMailserver 1.0 INweb ApS Mail Server 2.40 |
| Not Vulnerable: | |
Discussion
SoftiaCom WMailserver Remote Buffer Overflow Vulnerability
SoftiaCom WMailserver contains a remote buffer-overflow vulnerability in its connection-handling code. This issue is due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
If an attacker can connect to the SMTP service and send an excessive chunk of data, arbitrary machine code execution is possible. Failed exploitation attempts may result in crashing the application.
SoftiaCom WMailserver contains a remote buffer-overflow vulnerability in its connection-handling code. This issue is due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
If an attacker can connect to the SMTP service and send an excessive chunk of data, arbitrary machine code execution is possible. Failed exploitation attempts may result in crashing the application.
Exploit / POC
SoftiaCom WMailserver Remote Buffer Overflow Vulnerability
An exploit by y0 <[email protected]> (wmailserver_smtp.pm) for the Metasploit Framework is available:
http://downloads.securityfocus.com/vulnerabilities/exploits/wmailserver_smtp.pm
A proof of concept denial of service exploit by fRoGGz is available:
http://downloads.securityfocus.com/vulnerabilities/exploits/wMailServerDos.c
An exploit by y0 <[email protected]> (wmailserver_smtp.pm) for the Metasploit Framework is available:
http://downloads.securityfocus.com/vulnerabilities/exploits/wmailserver_smtp.pm
A proof of concept denial of service exploit by fRoGGz is available:
http://downloads.securityfocus.com/vulnerabilities/exploits/wMailServerDos.c
Solution / Fix
SoftiaCom WMailserver Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SoftiaCom WMailserver Remote Buffer Overflow Vulnerability
References:
References:
- INweb Mail Server Home Page (INweb ApS)
- InWebMAil 2.40 server Denial of Service (dr_insane)
- WMailserver Homepage (SoftiaCom)