Eremove Gui.CPP Remote Buffer Overflow Vulnerability
BID:19352
CVE-2006-4057 |Info
Eremove Gui.CPP Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 19352 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 04 2006 12:00AM |
| Updated: | Aug 04 2006 12:00AM |
| Credit: | Dedi Dwianto is credited with discovering this vulnerability. |
| Vulnerable: |
Mitch Murray Eremove 1.4 |
| Not Vulnerable: | |
Discussion
Eremove Gui.CPP Remote Buffer Overflow Vulnerability
Eremove is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check the message body of an email before copying it to an insufficiently sized memory buffer.
Successful exploits can allow remote attackers to execute arbitrary machine code in the context of the user running the application or to crash the application, resulting in a denial of service.
Eremove version 1.4 is vulnerable to this issue; other versions may also be affected.
Eremove is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check the message body of an email before copying it to an insufficiently sized memory buffer.
Successful exploits can allow remote attackers to execute arbitrary machine code in the context of the user running the application or to crash the application, resulting in a denial of service.
Eremove version 1.4 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Eremove Gui.CPP Remote Buffer Overflow Vulnerability
An exploit is not required.
An email with a 64-kilobyte message body can trigger a denial-of-service condition.
An exploit is not required.
An email with a 64-kilobyte message body can trigger a denial-of-service condition.
Solution / Fix
Eremove Gui.CPP Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any official vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any official vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].