No-Brainer SMTP Client Log_Msg() Remote Format String Vulnerability
BID:14441
Info
No-Brainer SMTP Client Log_Msg() Remote Format String Vulnerability
| Bugtraq ID: | 14441 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2005 12:00AM |
| Updated: | Aug 01 2005 12:00AM |
| Credit: | Niels Heinen is credited for the discovery of this vulnerability. |
| Vulnerable: |
nbSMTP nbSMTP 0.98 nbSMTP nbSMTP 0.97 nbSMTP nbSMTP 0.96 nbSMTP nbSMTP 0.95 nbSMTP nbSMTP 0.94 nbSMTP nbSMTP 0.93 nbSMTP nbSMTP 0.92 nbSMTP nbSMTP 0.91 nbSMTP nbSMTP 0.9 nbSMTP nbSMTP 0.8 Gentoo Linux |
| Not Vulnerable: |
nbSMTP nbSMTP 1.0 |
Discussion
No-Brainer SMTP Client Log_Msg() Remote Format String Vulnerability
A remote format string vulnerability affects the message logging functionality of nbSMTP. This issue is due to a failure of the application to properly sanitize user-supplied input prior to passing it as the format specifier to a formatted printing function.
A remote attacker may leverage this issue to write to arbitrary process memory, facilitating code execution.
A remote format string vulnerability affects the message logging functionality of nbSMTP. This issue is due to a failure of the application to properly sanitize user-supplied input prior to passing it as the format specifier to a formatted printing function.
A remote attacker may leverage this issue to write to arbitrary process memory, facilitating code execution.
Exploit / POC
No-Brainer SMTP Client Log_Msg() Remote Format String Vulnerability
The following proof of concept exploit by CoKi <[email protected]> has been made available:
The following proof of concept exploit by CoKi <[email protected]> has been made available:
Solution / Fix
No-Brainer SMTP Client Log_Msg() Remote Format String Vulnerability
Solution:
The vendor has released version 1.0 of the package to address this vulnerability.
Gentoo has released security advisory GLSA 200508-03 addressing this issue. Gentoo recommends all nbSMTP users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-mta/nbsmtp-1.0"
nbSMTP nbSMTP 0.8
nbSMTP nbSMTP 0.9
nbSMTP nbSMTP 0.91
nbSMTP nbSMTP 0.92
nbSMTP nbSMTP 0.93
nbSMTP nbSMTP 0.94
nbSMTP nbSMTP 0.95
nbSMTP nbSMTP 0.96
nbSMTP nbSMTP 0.97
nbSMTP nbSMTP 0.98
Solution:
The vendor has released version 1.0 of the package to address this vulnerability.
Gentoo has released security advisory GLSA 200508-03 addressing this issue. Gentoo recommends all nbSMTP users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-mta/nbsmtp-1.0"
nbSMTP nbSMTP 0.8
-
nbSMTP nbsmtp-1.00.tar.gz
http://www.gentoo-es.org/~ferdy/nbsmtp-1.00.tar.gz
nbSMTP nbSMTP 0.9
-
nbSMTP nbsmtp-1.00.tar.gz
http://www.gentoo-es.org/~ferdy/nbsmtp-1.00.tar.gz
nbSMTP nbSMTP 0.91
-
nbSMTP nbsmtp-1.00.tar.gz
http://www.gentoo-es.org/~ferdy/nbsmtp-1.00.tar.gz
nbSMTP nbSMTP 0.92
-
nbSMTP nbsmtp-1.00.tar.gz
http://www.gentoo-es.org/~ferdy/nbsmtp-1.00.tar.gz
nbSMTP nbSMTP 0.93
-
nbSMTP nbsmtp-1.00.tar.gz
http://www.gentoo-es.org/~ferdy/nbsmtp-1.00.tar.gz
nbSMTP nbSMTP 0.94
-
nbSMTP nbsmtp-1.00.tar.gz
http://www.gentoo-es.org/~ferdy/nbsmtp-1.00.tar.gz
nbSMTP nbSMTP 0.95
-
nbSMTP nbsmtp-1.00.tar.gz
http://www.gentoo-es.org/~ferdy/nbsmtp-1.00.tar.gz
nbSMTP nbSMTP 0.96
-
nbSMTP nbsmtp-1.00.tar.gz
http://www.gentoo-es.org/~ferdy/nbsmtp-1.00.tar.gz
nbSMTP nbSMTP 0.97
-
nbSMTP nbsmtp-1.00.tar.gz
http://www.gentoo-es.org/~ferdy/nbsmtp-1.00.tar.gz
nbSMTP nbSMTP 0.98
-
nbSMTP nbsmtp-1.00.tar.gz
http://www.gentoo-es.org/~ferdy/nbsmtp-1.00.tar.gz
References
No-Brainer SMTP Client Log_Msg() Remote Format String Vulnerability
References:
References:
- nbSMTP Home Page (nbSMTP)