GoodTech SMTP Server RCPT TO Multiple Remote Buffer Overflow Vulnerabilities
BID:14357
Info
GoodTech SMTP Server RCPT TO Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 14357 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2005 12:00AM |
| Updated: | Jul 23 2005 12:00AM |
| Credit: | Rapha?l Rigo <[email protected]> discovered this vulnerability |
| Vulnerable: |
GoodTech SMTP Server 5.16 GoodTech SMTP Server 5.15 |
| Not Vulnerable: |
GoodTech SMTP Server 5.17 |
Discussion
GoodTech SMTP Server RCPT TO Multiple Remote Buffer Overflow Vulnerabilities
GoodTech SMTP Server is susceptible to two remote buffer overflow vulnerabilities when handling RCPT TO commands. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to fixed size memory buffers.
These vulnerabilities allow remote attackers to execute arbitrary machine code with System level privileges in the context of the affected application.
GoodTech SMTP Server is susceptible to two remote buffer overflow vulnerabilities when handling RCPT TO commands. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to fixed size memory buffers.
These vulnerabilities allow remote attackers to execute arbitrary machine code with System level privileges in the context of the affected application.
Exploit / POC
GoodTech SMTP Server RCPT TO Multiple Remote Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
GoodTech SMTP Server RCPT TO Multiple Remote Buffer Overflow Vulnerabilities
Solution:
The reporter of this issue states that version 5.17 of the affected SMTP server software is not affected by this issue. Users of affected packages should upgrade to an unaffected version, and contact the vendor for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The reporter of this issue states that version 5.17 of the affected SMTP server software is not affected by this issue. Users of affected packages should upgrade to an unaffected version, and contact the vendor for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
GoodTech SMTP Server RCPT TO Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- SMTP Server Home Page (GoodTech Systems)
- GoodTech SMTP server 5.16 RCPT TO command remote buffer overflow (=?ISO-8859-1?Q?Rapha=EBl_Rigo?=
)