SurgeMail and WebMail 'Page' Command Remote Format String Vulnerability
BID:27990
Info
SurgeMail and WebMail 'Page' Command Remote Format String Vulnerability
| Bugtraq ID: | 27990 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1055 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Luigi Auriemma is credited with the discovery of this vulnerability. |
| Vulnerable: |
NetWin WebMail 3.1s NetWin SurgeMail 3.0 c2 NetWin SurgeMail 3.0 a NetWin SurgeMail 2.2 g3 NetWin SurgeMail 2.2 g2 NetWin SurgeMail 2.2 c9 NetWin SurgeMail 2.2 c10 NetWin SurgeMail 2.2 a6 NetWin SurgeMail 2.1 c7 NetWin SurgeMail 2.1 a NetWin SurgeMail 2.0 g2 NetWin SurgeMail 2.0 e NetWin SurgeMail 2.0 c NetWin SurgeMail 2.0 a2 NetWin SurgeMail 1.9 b2 NetWin SurgeMail 1.9 NetWin SurgeMail 1.8 g3 NetWin SurgeMail 1.8 e NetWin SurgeMail 1.8 d NetWin SurgeMail 1.8 b3 NetWin SurgeMail 1.8 a NetWin SurgeMail beta 39a NetWin SurgeMail 3.9a NetWin SurgeMail 3.8k4 NetWin SurgeMail 3.8f3 |
| Not Vulnerable: | |
Discussion
SurgeMail and WebMail 'Page' Command Remote Format String Vulnerability
SurgeMail and WebMail are prone to a remote format-string vulnerability because the applications fail to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.
A remote attacker may execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will result in a denial of service.
This issue affects the following:
SurgeMail 38k4, beta 39a and earlier
Netwin WebMail 3.1s and earlier
SurgeMail and WebMail are prone to a remote format-string vulnerability because the applications fail to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.
A remote attacker may execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will result in a denial of service.
This issue affects the following:
SurgeMail 38k4, beta 39a and earlier
Netwin WebMail 3.1s and earlier
Exploit / POC
SurgeMail and WebMail 'Page' Command Remote Format String Vulnerability
The following proof-of-concept exploit is available:
The following proof-of-concept exploit is available:
Solution / Fix
SurgeMail and WebMail 'Page' Command Remote Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SurgeMail and WebMail 'Page' Command Remote Format String Vulnerability
References:
References:
- Netwin Webmail Hompeage (Netwin)
- SurgeMail Homepage (Netwin)