QK SMTP Remote Buffer Overflow Vulnerability
BID:20681
Info
QK SMTP Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 20681 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 23 2006 12:00AM |
| Updated: | Jan 04 2007 06:26PM |
| Credit: | Greg Linares is credited with the discovery of this vulnerability. |
| Vulnerable: |
QKSoft QK SMTP 3.0.1 QKSoft QK SMTP 3.1.0 Beta |
| Not Vulnerable: | |
Discussion
QK SMTP Remote Buffer Overflow Vulnerability
QK SMTP is prone to a remote buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. This may facilitate a remote-compromise of affected computers. Failed exploit attempts will likely crash the server, effectively denying service to legitimate users.
QK SMTP 3.01 and prior versions are vulnerable to this issue.
QK SMTP is prone to a remote buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. This may facilitate a remote-compromise of affected computers. Failed exploit attempts will likely crash the server, effectively denying service to legitimate users.
QK SMTP 3.01 and prior versions are vulnerable to this issue.
Exploit / POC
QK SMTP Remote Buffer Overflow Vulnerability
The following exploits are available:
The following exploits are available:
Solution / Fix
QK SMTP Remote Buffer Overflow Vulnerability
Solution:
The vendor has released an update to address this issue. Please contact the vendor for details.
Solution:
The vendor has released an update to address this issue. Please contact the vendor for details.