YoungZSoft CMailServer Buffer Overflow Vulnerability
BID:4789
Info
YoungZSoft CMailServer Buffer Overflow Vulnerability
| Bugtraq ID: | 4789 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0799 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovered to [email protected]. |
| Vulnerable: |
YoungZSoft CMailServer 4.0 YoungZSoft CMailServer 3.30 |
| Not Vulnerable: | |
Discussion
YoungZSoft CMailServer Buffer Overflow Vulnerability
CMailServer is vulnerable to a buffer overflow condition. It has been reported that the CMailServer does not perform proper bounds checking on the USER argument.
It is possible for a remote malicious attacker to craft a request that will result in code execution on the vulnerable system.
This issue has been reported in CMailServer 3.30. Other versions may also be affected.
CMailServer is vulnerable to a buffer overflow condition. It has been reported that the CMailServer does not perform proper bounds checking on the USER argument.
It is possible for a remote malicious attacker to craft a request that will result in code execution on the vulnerable system.
This issue has been reported in CMailServer 3.30. Other versions may also be affected.
Exploit / POC
YoungZSoft CMailServer Buffer Overflow Vulnerability
The following exploit has been provided by <[email protected]>.
Another exploit has been provided by Over_G <[email protected]>.
The following exploit has been provided by <[email protected]>.
Another exploit has been provided by Over_G <[email protected]>.
Solution / Fix
YoungZSoft CMailServer Buffer Overflow Vulnerability
Solution:
A binary patch that has not been tested by SecurityFocus has been made available. See the message reference included in this record.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
A binary patch that has not been tested by SecurityFocus has been made available. See the message reference included in this record.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.