CREAR ALMail32 Buffer Overflow Vulnerability
BID:574
Info
CREAR ALMail32 Buffer Overflow Vulnerability
| Bugtraq ID: | 574 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-0673 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | Poste to the Shadow Penguin website August 8, 1999 by UNYUN. |
| Vulnerable: |
CREAR ALMail32 1.10 |
| Not Vulnerable: | |
Discussion
CREAR ALMail32 Buffer Overflow Vulnerability
The ALMail32 POP3 client conatins unchecked buffers in the header parsing code. An abnormally long FROM: or TO: field in the header of an incoming email will overwrite the buffer and allow arbitrary code to be executed.
The ALMail32 POP3 client conatins unchecked buffers in the header parsing code. An abnormally long FROM: or TO: field in the header of an incoming email will overwrite the buffer and allow arbitrary code to be executed.
Exploit / POC
Solution / Fix
CREAR ALMail32 Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
CREAR ALMail32 Buffer Overflow Vulnerability
References:
References:
- AL-Mail32 Ver1.10 Overflow Exploit on Windows9/NT (Shadow Penguin Security)