SLMail VRFY and EXPN Buffer Overflow Vulnerabilities
BID:223
Info
SLMail VRFY and EXPN Buffer Overflow Vulnerabilities
| Bugtraq ID: | 223 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Feb 04 1999 12:00AM |
| Updated: | Feb 04 1999 12:00AM |
| Credit: | This vulnerability was posted to NTBugtraq by Marc <[email protected]>. |
| Vulnerable: |
Seattle Lab Software SLMail 3.0.2421 |
| Not Vulnerable: | |
Discussion
SLMail VRFY and EXPN Buffer Overflow Vulnerabilities
The POP service of SLMail runs on tcp port 27. Issuing a 'vrfy' or 'expn' command followed by 2041 characters will cause the SLMail service to stop functioning. It is not known what other character lengths will cause this service to crash.
The POP service of SLMail runs on tcp port 27. Issuing a 'vrfy' or 'expn' command followed by 2041 characters will cause the SLMail service to stop functioning. It is not known what other character lengths will cause this service to crash.
Exploit / POC
SLMail VRFY and EXPN Buffer Overflow Vulnerabilities
see discussion
see discussion
Solution / Fix
SLMail VRFY and EXPN Buffer Overflow Vulnerabilities
Solution:
Contact Seattle Labs (www.seattlelab.com) for a patch.
Solution:
Contact Seattle Labs (www.seattlelab.com) for a patch.
References
SLMail VRFY and EXPN Buffer Overflow Vulnerabilities
References:
References: