Youngzsoft CMailServer MAIL FROM Buffer Overflow Vulnerability
BID:7547
Info
Youngzsoft CMailServer MAIL FROM Buffer Overflow Vulnerability
| Bugtraq ID: | 7547 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2003 12:00AM |
| Updated: | May 10 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Dennis Rand" <[email protected]>. |
| Vulnerable: |
YoungZSoft CMailServer 4.0 .2003.03.27 YoungZSoft CMailServer 4.0 .2002.11.24 |
| Not Vulnerable: |
YoungZSoft CMailServer 4.0 .2003.03.30 |
Discussion
Youngzsoft CMailServer MAIL FROM Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for CMailServer. The vulnerability exists due to insufficient bounds checking when parsing e-mail headers. Specifically, an overly long MAIL FROM e-mail header will cause CMailServer to crash and corrupt sensitive memory.
A buffer overflow vulnerability has been reported for CMailServer. The vulnerability exists due to insufficient bounds checking when parsing e-mail headers. Specifically, an overly long MAIL FROM e-mail header will cause CMailServer to crash and corrupt sensitive memory.
Exploit / POC
Youngzsoft CMailServer MAIL FROM Buffer Overflow Vulnerability
The following exploit was provided:
The following exploit was provided:
Solution / Fix
Youngzsoft CMailServer MAIL FROM Buffer Overflow Vulnerability
Solution:
Users are advised to contact the vendor for upgrade information.
Solution:
Users are advised to contact the vendor for upgrade information.
References
Youngzsoft CMailServer MAIL FROM Buffer Overflow Vulnerability
References:
References:
- CMailServer Homepage (YoungZSoft)
- Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0 ("Dennis Rand"
)