BVRP SLMail Remote POPPASSWD Buffer Overrun Vulnerability
BID:7512
Info
BVRP SLMail Remote POPPASSWD Buffer Overrun Vulnerability
| Bugtraq ID: | 7512 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2003 12:00AM |
| Updated: | May 07 2003 12:00AM |
| Credit: | Discovery credited to "NGSSoftware Insight Security Research" <[email protected]>. |
| Vulnerable: |
BVRP Software SLMail 5.1 .0.4420 |
| Not Vulnerable: |
BVRP Software SLMail 5.5 |
Discussion
BVRP SLMail Remote POPPASSWD Buffer Overrun Vulnerability
It has been reported that a boundary condition error exists in SLMail. A remote attacker sending a string of excessive length to the POPPasswd service may cause a buffer overrun that could result in execution of malicious instructions and system compromise.
It has been reported that a boundary condition error exists in SLMail. A remote attacker sending a string of excessive length to the POPPasswd service may cause a buffer overrun that could result in execution of malicious instructions and system compromise.
Exploit / POC
BVRP SLMail Remote POPPASSWD Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
BVRP SLMail Remote POPPASSWD Buffer Overrun Vulnerability
Solution:
It has been reported that the vendor has fixed this problem in version 5.5. This has not been confirmed by the vendor.
BVRP Software SLMail 5.1 .0.4420
Solution:
It has been reported that the vendor has fixed this problem in version 5.5. This has not been confirmed by the vendor.
BVRP Software SLMail 5.1 .0.4420
-
BVRP Software SLMail 5.5
http://www.slmail.com
References
BVRP SLMail Remote POPPASSWD Buffer Overrun Vulnerability
References:
References:
- Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A) ("NGSSoftware Insight Security Research"
)