Pegasus Mail Multiple Remote Code Execution Vulnerabilities
BID:15973
Info
Pegasus Mail Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 15973 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2005 12:00AM |
| Updated: | Dec 20 2005 12:00AM |
| Credit: | Discovered by Tan Chew Keong, Secunia Research. |
| Vulnerable: |
David Harris Pegasus Mail 4.30 PB1 David Harris Pegasus Mail 4.21 c |
| Not Vulnerable: |
David Harris Pegasus Mail 4.31 |
Discussion
Pegasus Mail Multiple Remote Code Execution Vulnerabilities
Pegasus Mail is prone to multiple remote code execution vulnerabilities.
The following specific vulnerabilities were identified:
A buffer overflow vulnerability arises when the application handles a malformed POP3 reply from a server.
An off-by-one buffer overflow vulnerability arises when the application handles a malicious email message.
Pegasus Mail 4.21c and 4.30PB1 are reportedly vulnerable. Other versions may be affected as well.
Pegasus Mail is prone to multiple remote code execution vulnerabilities.
The following specific vulnerabilities were identified:
A buffer overflow vulnerability arises when the application handles a malformed POP3 reply from a server.
An off-by-one buffer overflow vulnerability arises when the application handles a malicious email message.
Pegasus Mail 4.21c and 4.30PB1 are reportedly vulnerable. Other versions may be affected as well.
Exploit / POC
Pegasus Mail Multiple Remote Code Execution Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Pegasus Mail Multiple Remote Code Execution Vulnerabilities
Solution:
The vendor has released Pegasus Mail 4.31 to address these issues.
David Harris Pegasus Mail 4.21 c
David Harris Pegasus Mail 4.30 PB1
Solution:
The vendor has released Pegasus Mail 4.31 to address these issues.
David Harris Pegasus Mail 4.21 c
-
David Harris Pegasus Mail 4.31
ftp://ftp.usm.maine.edu/pegasus/winpmail/w32-431.exe
David Harris Pegasus Mail 4.30 PB1
-
David Harris Pegasus Mail 4.31
ftp://ftp.usm.maine.edu/pegasus/winpmail/w32-431.exe
References
Pegasus Mail Multiple Remote Code Execution Vulnerabilities
References:
References:
- Pegasus Mail Product Homepage (David Harris)
- Secunia Research: Pegasus Mail Buffer Overflow and Off-by-One Vulnerabilities (Secunia Research
)