SLMail Remote ETRN Command Buffer Overflow Vulnerability
BID:7515
Info
SLMail Remote ETRN Command Buffer Overflow Vulnerability
| Bugtraq ID: | 7515 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2003 12:00AM |
| Updated: | May 07 2003 12:00AM |
| Credit: | Discovery credited to "NGSSoftware Insight Security Research" <[email protected]>. |
| Vulnerable: |
BVRP Software SLMail 5.1 .0.4420 |
| Not Vulnerable: | |
Discussion
SLMail Remote ETRN Command Buffer Overflow Vulnerability
A remotely exploitable vulnerability has been discovered in SLMail. The problem occurs in the ETRN command. Specifically, due to insufficient bounds checking while processing ETRN command parameters it may be possible to trigger a buffer overflow. Successful exploitation of this issue may result in the corruption of sensitive memory locations and the execution of arbitrary code with the privileges of SLMail.
A remotely exploitable vulnerability has been discovered in SLMail. The problem occurs in the ETRN command. Specifically, due to insufficient bounds checking while processing ETRN command parameters it may be possible to trigger a buffer overflow. Successful exploitation of this issue may result in the corruption of sensitive memory locations and the execution of arbitrary code with the privileges of SLMail.
Exploit / POC
SLMail Remote ETRN Command Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SLMail Remote ETRN Command Buffer Overflow Vulnerability
Solution:
It has been reported that the vendor has fixed this problem in version 5.5. This has not been confirmed by the vendor.
Solution:
It has been reported that the vendor has fixed this problem in version 5.5. This has not been confirmed by the vendor.
References
SLMail Remote ETRN Command Buffer Overflow Vulnerability
References:
References:
- Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A) ("NGSSoftware Insight Security Research"
)