RevilloC MailServer Remote SMTP Buffer Overflow Vulnerability
BID:20709
Info
RevilloC MailServer Remote SMTP Buffer Overflow Vulnerability
| Bugtraq ID: | 20709 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2006 12:00AM |
| Updated: | Oct 26 2006 09:03PM |
| Credit: | Discovered by Greg Linares <[email protected]>. |
| Vulnerable: |
RevilloC MailServer 1.21 |
| Not Vulnerable: | |
Discussion
RevilloC MailServer Remote SMTP Buffer Overflow Vulnerability
RevilloC MailServer is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue likely allows remote attackers to execute arbitrary machine code with elevated privileges, facilitating the complete remote compromise of affected computers. Failed exploit attempts will crash the application.
Specific version information is not currently available; this BID will be updated as more information is disclosed.
RevilloC MailServer is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue likely allows remote attackers to execute arbitrary machine code with elevated privileges, facilitating the complete remote compromise of affected computers. Failed exploit attempts will crash the application.
Specific version information is not currently available; this BID will be updated as more information is disclosed.
Exploit / POC
RevilloC MailServer Remote SMTP Buffer Overflow Vulnerability
Exploit code is available.
Exploit code is available.
Solution / Fix
RevilloC MailServer Remote SMTP Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
RevilloC MailServer Remote SMTP Buffer Overflow Vulnerability
References:
References:
- RevilloC MailServer (RevilloC)