Michael Krax log2mail Remote Buffer Overflow Vulnerability
BID:6089
Info
Michael Krax log2mail Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 6089 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1251 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery of this vulnerability has been credited to Enrico Zini. |
| Vulnerable: |
log2mail log2mail 0.2.5 .0 |
| Not Vulnerable: |
log2mail log2mail 0.2.7 log2mail log2mail 0.2.6 log2mail log2mail 0.2.5 .1 |
Discussion
Michael Krax log2mail Remote Buffer Overflow Vulnerability
A remotely exploitable buffer overflow has been discovered in the log2mail daemon. By generating a malicious log entry, it is possible for a remote attacker to overrun a static buffer in log2mail, potentially resulting in the corruption of sensitive memory values.
By exploiting this vulnerability, it may be possible to overwrite sensitive memory variables with attacker-supplied values, resulting in the execution of arbitrary code with the privileges of the daemon.
This vulnerability was reported in log2mail v0.2.5. It is not yet known if this issue affects earlier versions.
A remotely exploitable buffer overflow has been discovered in the log2mail daemon. By generating a malicious log entry, it is possible for a remote attacker to overrun a static buffer in log2mail, potentially resulting in the corruption of sensitive memory values.
By exploiting this vulnerability, it may be possible to overwrite sensitive memory variables with attacker-supplied values, resulting in the execution of arbitrary code with the privileges of the daemon.
This vulnerability was reported in log2mail v0.2.5. It is not yet known if this issue affects earlier versions.
Exploit / POC
Michael Krax log2mail Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Michael Krax log2mail Remote Buffer Overflow Vulnerability
Solution:
Debian has released a security advisory containing fixes.
Fixes:
Solution:
Debian has released a security advisory containing fixes.
Fixes: