SurgeMail Real CGI executables Remote Buffer Overflow Vulnerability
BID:27992
Info
SurgeMail Real CGI executables Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 27992 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1054 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Luigi Auriemma discovered this vulnerability. |
| Vulnerable: |
NetWin SurgeMail 3.0 c2 NetWin SurgeMail 3.0 a NetWin SurgeMail 2.2 g3 NetWin SurgeMail 2.2 g2 NetWin SurgeMail 2.2 c9 NetWin SurgeMail 2.2 c10 NetWin SurgeMail 2.2 a6 NetWin SurgeMail 2.1 c7 NetWin SurgeMail 2.1 a NetWin SurgeMail 2.0 g2 NetWin SurgeMail 2.0 e NetWin SurgeMail 2.0 c NetWin SurgeMail 2.0 a2 NetWin SurgeMail 1.9 b2 NetWin SurgeMail 1.9 NetWin SurgeMail 1.8 g3 NetWin SurgeMail 1.8 e NetWin SurgeMail 1.8 d NetWin SurgeMail 1.8 b3 NetWin SurgeMail 1.8 a NetWin SurgeMail 38k4 NetWin SurgeMail 3.8k NetWin SurgeMail 3.8i3 NetWin SurgeMail 3.8i2 NetWin SurgeMail 3.8i NetWin SurgeMail 3.8f3 NetWin SurgeMail 3.1s |
| Not Vulnerable: | |
Discussion
SurgeMail Real CGI executables Remote Buffer Overflow Vulnerability
SurgeMail is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected service. Failed exploit attempts likely result in denial-of-service conditions.
SurgeMail 38k4 and prior versions are vulnerable.
SurgeMail is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected service. Failed exploit attempts likely result in denial-of-service conditions.
SurgeMail 38k4 and prior versions are vulnerable.
Exploit / POC
SurgeMail Real CGI executables Remote Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept exploit is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept exploit is available:
Solution / Fix
SurgeMail Real CGI executables Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SurgeMail Real CGI executables Remote Buffer Overflow Vulnerability
References:
References:
- SurgeMail Homepage (Netwin)
- Format string and buffer-overflow in SurgeMail 38k4 (Luigi Auriemma
)