Novell NetMail and M+NetMail Antivirus Agent Multiple Heap Buffer Overflow Vulnerabilities
BID:26753
Info
Novell NetMail and M+NetMail Antivirus Agent Multiple Heap Buffer Overflow Vulnerabilities
| Bugtraq ID: | 26753 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6302 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2007 12:00AM |
| Updated: | Dec 11 2007 02:02PM |
| Credit: | The vendor credits Brian Schafer with the discovery of these vulnerabilities. |
| Vulnerable: |
Novell NetMail 3.52 E Novell NetMail 3.52 D Novell NetMail 3.52 C1 Novell NetMail 3.52 C Novell NetMail 3.52 B Novell NetMail 3.52 A Novell NetMail 3.52 Novell NetMail 3.52e-ftfl Novell NetMail 3.52e _FTF2 Messaging Architects M+Netmail 3.52 |
| Not Vulnerable: |
Messaging Architects M+Netmail 3.52.F |
Discussion
Novell NetMail and M+NetMail Antivirus Agent Multiple Heap Buffer Overflow Vulnerabilities
Novell NetMail and M+NetMail are prone to multiple heap-based buffer-overflow vulnerabilities. These issues occur because the applications fail to perform adequate boundary checks on user-supplied data.
A successful exploit will allow remote attackers to execute arbitrary code in the context of the affected software. Failed exploit attempts may result in denial-of-service conditions.
Novell NetMail and M+NetMail are prone to multiple heap-based buffer-overflow vulnerabilities. These issues occur because the applications fail to perform adequate boundary checks on user-supplied data.
A successful exploit will allow remote attackers to execute arbitrary code in the context of the affected software. Failed exploit attempts may result in denial-of-service conditions.
Exploit / POC
Novell NetMail and M+NetMail Antivirus Agent Multiple Heap Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Novell NetMail and M+NetMail Antivirus Agent Multiple Heap Buffer Overflow Vulnerabilities
Solution:
Novell released an advisory, but not a patch.
Messaging Architects, the new owner of the application, has released M+NetMail 3.52F to address this issue.
Please see the references and contact the vendor(s) for more information.
Messaging Architects M+Netmail 3.52
Solution:
Novell released an advisory, but not a patch.
Messaging Architects, the new owner of the application, has released M+NetMail 3.52F to address this issue.
Please see the references and contact the vendor(s) for more information.
Messaging Architects M+Netmail 3.52
-
Messaging Architects M+NetMail 3.5.2F Patch for Linux
http://www.messagingarchitects.com/en/sales/files/netmail352f_lin.tgz -
Messaging Architects M+NetMail 3.5.2F Patch for NetWare
http://www.messagingarchitects.com/en/sales/files/netmail352f_nw.zip -
Messaging Architects M+NetMail 3.5.2F Patch for Windows
http://www.messagingarchitects.com/en/sales/files/netmail352f_win.zip
References
Novell NetMail and M+NetMail Antivirus Agent Multiple Heap Buffer Overflow Vulnerabilities
References:
References:
- M+Netmail (Messaging Architects)
- NetMail Product Page (Novell)
- ZDI-07-072: Novell Netmail AntiVirus Agent Multiple Overflow Vulnerabilities ([email protected])
- Novell NetMail AntiVirus Agent Multiple Heap Overflow Vulnerabilities (Zero Day Initiative)
- Potential Security Vulnerability in NetMail 3.5.2 (Novell )
- ZDI Upcoming Advisories (ZDI)