BVRP SLWebMail LANGUAGE Variable Buffer Overflow Vulnerability
BID:7524
Info
BVRP SLWebMail LANGUAGE Variable Buffer Overflow Vulnerability
| Bugtraq ID: | 7524 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2003 12:00AM |
| Updated: | May 07 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to H D Moore <[email protected]>. |
| Vulnerable: |
BVRP Software SLWebMail 3 |
| Not Vulnerable: | |
Discussion
BVRP SLWebMail LANGUAGE Variable Buffer Overflow Vulnerability
A remotely exploitable vulnerability has been reported for SLWebMail. The problem is said to occur in multiple libraries. Specifically, due to insufficient bounds checking while processing the LANGUAGE variable it may be possible to trigger a buffer overflow in one of multiple libraries. Successful exploitation of this issue may result in the corruption of sensitive memory locations and the execution of arbitrary code with the privileges of SLWebMail.
A remotely exploitable vulnerability has been reported for SLWebMail. The problem is said to occur in multiple libraries. Specifically, due to insufficient bounds checking while processing the LANGUAGE variable it may be possible to trigger a buffer overflow in one of multiple libraries. Successful exploitation of this issue may result in the corruption of sensitive memory locations and the execution of arbitrary code with the privileges of SLWebMail.
Solution / Fix
BVRP SLWebMail LANGUAGE Variable Buffer Overflow Vulnerability
Solution:
Although unconfirmed, this issue may be fixed in an updated version. Users are advised to contact the vendor for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Although unconfirmed, this issue may be fixed in an updated version. Users are advised to contact the vendor for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.