CGIEmail Remote Buffer Overflow Vulnerability
BID:6141
Info
CGIEmail Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 6141 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2001 12:00AM |
| Updated: | Sep 11 2001 12:00AM |
| Credit: | This vulnerability was reported in a SecurityTracker advisory. |
| Vulnerable: |
MIT cgiemail 1.6 |
| Not Vulnerable: | |
Discussion
CGIEmail Remote Buffer Overflow Vulnerability
A vulnerability has been discovered in CGIEmail. It should be noted that this vulnerability exists only if the server allows queries to remote hosts.
A remotely exploitable buffer overflow has been discovered in a component included with CGIEmail. By sending a maliciously constructed GET request to the vulnerable server, it is possible for a remote attacker to overrun a buffer, potentially resulting in the execution of arbitrary system commands with the privileges of the mail server.
A vulnerability has been discovered in CGIEmail. It should be noted that this vulnerability exists only if the server allows queries to remote hosts.
A remotely exploitable buffer overflow has been discovered in a component included with CGIEmail. By sending a maliciously constructed GET request to the vulnerable server, it is possible for a remote attacker to overrun a buffer, potentially resulting in the execution of arbitrary system commands with the privileges of the mail server.
Exploit / POC
CGIEmail Remote Buffer Overflow Vulnerability
An exploit has been made available.
An exploit has been made available.
Solution / Fix
CGIEmail Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
CGIEmail Remote Buffer Overflow Vulnerability
References:
References: