Libremail Pop.c Remote Format String Vulnerability
BID:15906
Info
Libremail Pop.c Remote Format String Vulnerability
| Bugtraq ID: | 15906 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2005 12:00AM |
| Updated: | Dec 16 2005 12:00AM |
| Credit: | Discovered by Mehdi Oudad "deepfear" from the Zone-H Research Team. |
| Vulnerable: |
Libremail Libremail 1.1 |
| Not Vulnerable: | |
Discussion
Libremail Pop.c Remote Format String Vulnerability
Libremail is susceptible to a remote format string vulnerability.
This issue presents itself in the 'pop.c' file, when the application processes specially crafted data from a POP server.
This issue allows remote attackers to execute arbitrary machine code in the context of the affected application. A denial of service condition may arise due to failed exploitation attempts as well.
Libremail 1.1.0 and prior versions are affected.
Libremail is susceptible to a remote format string vulnerability.
This issue presents itself in the 'pop.c' file, when the application processes specially crafted data from a POP server.
This issue allows remote attackers to execute arbitrary machine code in the context of the affected application. A denial of service condition may arise due to failed exploitation attempts as well.
Libremail 1.1.0 and prior versions are affected.
Exploit / POC
Libremail Pop.c Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Libremail Pop.c Remote Format String Vulnerability
Solution:
The vendor has released updated source code files to address this issue. Users are advised to obtain updates files from the following location:
http://libremail.tuxfamily.org/en/dersources.htm
Solution:
The vendor has released updated source code files to address this issue. Users are advised to obtain updates files from the following location:
http://libremail.tuxfamily.org/en/dersources.htm
References
Libremail Pop.c Remote Format String Vulnerability
References:
References: