NullLogic Null Webmail Format String Vulnerability
BID:5794
Info
NullLogic Null Webmail Format String Vulnerability
| Bugtraq ID: | 5794 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2002 12:00AM |
| Updated: | Sep 25 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to DownBload <[email protected]>. |
| Vulnerable: |
NullLogic Null Webmail 0.6.4 |
| Not Vulnerable: | |
Discussion
NullLogic Null Webmail Format String Vulnerability
A format string vulnerability has been reported for Null Webmail 0.64. Allegedly, there exists errors in the server code. By supplying maliciously contructed format strings to the vulnerable functions, it may be possible to corrupt memory with attacker-supplied data. This may result in arbitrary code execution with the privileges of the server.
A format string vulnerability has been reported for Null Webmail 0.64. Allegedly, there exists errors in the server code. By supplying maliciously contructed format strings to the vulnerable functions, it may be possible to corrupt memory with attacker-supplied data. This may result in arbitrary code execution with the privileges of the server.
Exploit / POC
NullLogic Null Webmail Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
NullLogic Null Webmail Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.