Axigen AXIMilter Filtering Module Remote Format String Vulnerability
BID:27363
Info
Axigen AXIMilter Filtering Module Remote Format String Vulnerability
| Bugtraq ID: | 27363 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0434 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2008 12:00AM |
| Updated: | May 08 2008 09:25PM |
| Credit: | hempel is credited with the discovery of this issue. |
| Vulnerable: |
Axigen Axigen Mail Server 5.0.2 Axigen Axigen Mail Server 5.0.1 |
| Not Vulnerable: |
Axigen Axigen Mail Server 5.0.2 build 2 |
Discussion
Axigen AXIMilter Filtering Module Remote Format String Vulnerability
Axigen is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function. Specifically, the issue affects the AXIMilter module.
Successfully exploiting this issue allows remote, unauthenticated attackers to execute arbitrary code in the context of the application. Failed attempts may cause denial-of-service conditions.
This issue affects Axigen 5.0.2; other versions may also be vulnerable.
Axigen is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function. Specifically, the issue affects the AXIMilter module.
Successfully exploiting this issue allows remote, unauthenticated attackers to execute arbitrary code in the context of the application. Failed attempts may cause denial-of-service conditions.
This issue affects Axigen 5.0.2; other versions may also be vulnerable.
Exploit / POC
Axigen AXIMilter Filtering Module Remote Format String Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Axigen AXIMilter Filtering Module Remote Format String Vulnerability
Solution:
The vendor has released fixes. Please contact the vendor for information on how to obtain the latest version.
Solution:
The vendor has released fixes. Please contact the vendor for information on how to obtain the latest version.
References
Axigen AXIMilter Filtering Module Remote Format String Vulnerability
References:
References:
- Axigen Mail Server Web Site (Axigen)
- AXIGEN 5.0.x AXIMilter Format String Exploit ( "hempel"
)