GFI MailSecurity for Exchange/SMTP Web Interface Remote Buffer Overflow Vulnerability
BID:15081
Info
GFI MailSecurity for Exchange/SMTP Web Interface Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 15081 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2005 12:00AM |
| Updated: | Oct 12 2005 12:00AM |
| Credit: | Discovery is credited to Gary Oleary-Steele <[email protected]>. |
| Vulnerable: |
GFI MailSecurity for Exchange/SMTP 8.1 |
| Not Vulnerable: | |
Discussion
GFI MailSecurity for Exchange/SMTP Web Interface Remote Buffer Overflow Vulnerability
GFI MailSecurity for Exchange/SMTP is affected by a remote buffer overflow vulnerability.
Specifically, the issue presents itself when the Web management interface of the application handles malformed HTTP requests.
A successful attack can result in a complete compromise of the vulnerable computer.
GFI MailSecurity for Exchange/SMTP version 8.1 is vulnerable to this issue.
GFI MailSecurity for Exchange/SMTP is affected by a remote buffer overflow vulnerability.
Specifically, the issue presents itself when the Web management interface of the application handles malformed HTTP requests.
A successful attack can result in a complete compromise of the vulnerable computer.
GFI MailSecurity for Exchange/SMTP version 8.1 is vulnerable to this issue.
Exploit / POC
GFI MailSecurity for Exchange/SMTP Web Interface Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
GFI MailSecurity for Exchange/SMTP Web Interface Remote Buffer Overflow Vulnerability
Solution:
The vendor has released a patch to address this issue.
GFI MailSecurity for Exchange/SMTP 8.1
Solution:
The vendor has released a patch to address this issue.
GFI MailSecurity for Exchange/SMTP 8.1
-
GFI MSEC8_PATCH_20050919_01.zip
ftp://ftp.gfi.com/patches/MSEC8_PATCH_20050919_01.zip
References
GFI MailSecurity for Exchange/SMTP Web Interface Remote Buffer Overflow Vulnerability
References:
References:
- MailSecurity Product Page (GFI)
- New GFI MailSecurity 8.1 patch released (GFI)
- GFI MailSecurity 8.1 Web Module Buffer Overflow ("Gary Oleary-Steele"
)