MailEnable 'MEHTTPS.EXE' Stack-Based Buffer Overflow Vulnerability
BID:36197
Info
MailEnable 'MEHTTPS.EXE' Stack-Based Buffer Overflow Vulnerability
| Bugtraq ID: | 36197 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 31 2009 12:00AM |
| Updated: | Sep 01 2009 03:12PM |
| Credit: | fl0 fl0w |
| Vulnerable: |
MailEnable MailEnable Professional 1.52 |
| Not Vulnerable: | |
Discussion
MailEnable 'MEHTTPS.EXE' Stack-Based Buffer Overflow Vulnerability
MailEnable is prone to a stack-based buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker could exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
MailEnable 1.52 is vulnerable; other versions may also be affected.
MailEnable is prone to a stack-based buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker could exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
MailEnable 1.52 is vulnerable; other versions may also be affected.
Exploit / POC
MailEnable 'MEHTTPS.EXE' Stack-Based Buffer Overflow Vulnerability
The following proof-of-concept code is available:
The following proof-of-concept code is available:
Solution / Fix
MailEnable 'MEHTTPS.EXE' Stack-Based Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MailEnable 'MEHTTPS.EXE' Stack-Based Buffer Overflow Vulnerability
References:
References:
- MailEnable Homepage (MailEnable)