SLMail 3.0.2421 Buffer Overflow 'Mail From' Vulnerability
BID:153
Info
SLMail 3.0.2421 Buffer Overflow 'Mail From' Vulnerability
| Bugtraq ID: | 153 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Jul 09 1998 12:00AM |
| Updated: | Jul 09 1998 12:00AM |
| Credit: | An excellent post on this vulnerability was posted to NTBugtraq on July 8, 1998 by it's author, Ezekial Morrow <[email protected]> |
| Vulnerable: |
Seattle Lab Software SLMail 3.0.2421 |
| Not Vulnerable: | |
Discussion
SLMail 3.0.2421 Buffer Overflow 'Mail From' Vulnerability
A buffer overflow exists in Seattle Lab Software's SLMail program that allow an attacker to potential run arbitrary commands on any NT machine which has SLMail installed. By failing to properly bound the length of the "mail from" field, SLMail is left vulnerable to a stack overrun.
This is an exploitable overflow -- the author of the advisory gave extensive description to how one would go about writing an exploit for this problem, but did not publish an exploit. It should not be assumed, however, that exploits do not exist.
A buffer overflow exists in Seattle Lab Software's SLMail program that allow an attacker to potential run arbitrary commands on any NT machine which has SLMail installed. By failing to properly bound the length of the "mail from" field, SLMail is left vulnerable to a stack overrun.
This is an exploitable overflow -- the author of the advisory gave extensive description to how one would go about writing an exploit for this problem, but did not publish an exploit. It should not be assumed, however, that exploits do not exist.
Exploit / POC
SLMail 3.0.2421 Buffer Overflow 'Mail From' Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SLMail 3.0.2421 Buffer Overflow 'Mail From' Vulnerability
Solution:
The only solution to this vulnerability is to either disable SLMail, or upgrade to a later version. Patch information is available at http://www.seattlelab.com/
Solution:
The only solution to this vulnerability is to either disable SLMail, or upgrade to a later version. Patch information is available at http://www.seattlelab.com/
References
SLMail 3.0.2421 Buffer Overflow 'Mail From' Vulnerability
References:
References:
- Seattle Labs Home Page (Seattle Labs)