Ipswitch Collaboration Suite and IMail Server SMTPD Remote Format String Vulnerability
BID:15752
Info
Ipswitch Collaboration Suite and IMail Server SMTPD Remote Format String Vulnerability
| Bugtraq ID: | 15752 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2931 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2005 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | Nico is credited for the discovery of this issue. |
| Vulnerable: |
Ipswitch Ipswitch Collaboration Suite 2.0 1 Ipswitch Ipswitch Collaboration Suite Ipswitch IMail 8.20 |
| Not Vulnerable: |
Ipswitch Ipswitch Collaboration Suite 2.0 2 Ipswitch IMail 8.22 |
Discussion
Ipswitch Collaboration Suite and IMail Server SMTPD Remote Format String Vulnerability
Ipswitch Collaboration Suite and IMail Server are susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in a format-specifier argument to a formatted printing function.
This issue allows remote attackers to execute arbitrary machine code in the context of the affected application.
Ipswitch Collaboration Suite and IMail Server are susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in a format-specifier argument to a formatted printing function.
This issue allows remote attackers to execute arbitrary machine code in the context of the affected application.
Exploit / POC
Ipswitch Collaboration Suite and IMail Server SMTPD Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Ipswitch Collaboration Suite and IMail Server SMTPD Remote Format String Vulnerability
Solution:
The vendor has released fixes to address this issue:
Ipswitch Ipswitch Collaboration Suite 2.0 1
Ipswitch IMail 8.20
Solution:
The vendor has released fixes to address this issue:
Ipswitch Ipswitch Collaboration Suite 2.0 1
-
Ipswitch Ipswitch Collaboration Suite 2.02
http://www.ipswitch.com/support/ics/updates/ics202.asp
Ipswitch IMail 8.20
-
Ipswitch IMail Server 8.22 Patch
http://www.ipswitch.com/support/imail/releases/imail_professional/im82 2.asp
References
Ipswitch Collaboration Suite and IMail Server SMTPD Remote Format String Vulnerability
References:
References: