Incognito Systems ISMTP Gateway Buffer Overflow Vulnerability
BID:6151
Info
Incognito Systems ISMTP Gateway Buffer Overflow Vulnerability
| Bugtraq ID: | 6151 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2002 12:00AM |
| Updated: | Nov 11 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "K. K. Mookhey" <[email protected]>. |
| Vulnerable: |
Incognito Software Inc iSMTP Gateway 5.0.1 |
| Not Vulnerable: | |
Discussion
Incognito Systems ISMTP Gateway Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for iSMTP Gateway. The vulnerability occurs due to inappropriate bounds checking when processing user-supplied input.
An attacker can exploit this vulnerability by sending an overly long command to the vulnerable system. When the system receives this input it will crash.
It may be possible that code execution may be possible, however, this has not been confirmed.
A buffer overflow vulnerability has been reported for iSMTP Gateway. The vulnerability occurs due to inappropriate bounds checking when processing user-supplied input.
An attacker can exploit this vulnerability by sending an overly long command to the vulnerable system. When the system receives this input it will crash.
It may be possible that code execution may be possible, however, this has not been confirmed.
Exploit / POC
Incognito Systems ISMTP Gateway Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Incognito Systems ISMTP Gateway Buffer Overflow Vulnerability
Solution:
The vendor has stated that the vulnerability does not affect the latest version of iSMTP Gateway. Customers are advised to contact Incognito Software Inc for information about obtaining the latest version of the software.
Solution:
The vendor has stated that the vulnerability does not affect the latest version of iSMTP Gateway. Customers are advised to contact Incognito Software Inc for information about obtaining the latest version of the software.
References
Incognito Systems ISMTP Gateway Buffer Overflow Vulnerability
References:
References:
- Home Page (Incognito Software Inc.)
- Buffer Overflow in iSMTP Gateway ("K. K. Mookhey"
)