Citadel SMTP RCPT TO Remote Buffer Overflow Vulnerability
BID:27376
Info
Citadel SMTP RCPT TO Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 27376 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0394 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2007 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | prdelka is credited with discovering this issue. |
| Vulnerable: |
Citadel/UX Citadel/UX 6.30 Citadel/UX Citadel/UX 6.29 Citadel/UX Citadel/UX 6.27 Citadel/UX Citadel/UX 6.26 Citadel/UX Citadel/UX 6.24 Citadel/UX Citadel/UX 6.23 Citadel/UX Citadel/UX 6.0 8 Citadel/UX Citadel/UX 6.0 7 Citadel/UX Citadel/UX 5.91 Citadel/UX Citadel/UX 5.90 Citadel/UX Citadel/UX 7.10 |
| Not Vulnerable: |
Citadel/UX Citadel/UX 7.11 |
Discussion
Citadel SMTP RCPT TO Remote Buffer Overflow Vulnerability
Citadel is prone to a buffer-overflow vulnerability because the software fails to properly bounds-check user-supplied input before copying it into an insufficiently sized memory buffer.
Attackers may exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Versions prior to Citadel 7.11 are vulnerable to this issue.
Citadel is prone to a buffer-overflow vulnerability because the software fails to properly bounds-check user-supplied input before copying it into an insufficiently sized memory buffer.
Attackers may exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Versions prior to Citadel 7.11 are vulnerable to this issue.
Exploit / POC
Citadel SMTP RCPT TO Remote Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Citadel SMTP RCPT TO Remote Buffer Overflow Vulnerability
Solution:
The vendor has released Citadel 7.11 to address this issue. Please see the references for more information.
Solution:
The vendor has released Citadel 7.11 to address this issue. Please see the references for more information.
References
Citadel SMTP RCPT TO Remote Buffer Overflow Vulnerability
References:
References:
- Citadel/UX Homepage (Citadel/UX)