Mailtraq Remote Format String SMTP Resource Consumption Vulnerability
BID:7926
Info
Mailtraq Remote Format String SMTP Resource Consumption Vulnerability
| Bugtraq ID: | 7926 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2003 12:00AM |
| Updated: | Jun 16 2003 12:00AM |
| Credit: | Discovery credited to Noam Rathaus. |
| Vulnerable: |
Mailtraq Mailtraq 2.1 .0.1302 |
| Not Vulnerable: | |
Discussion
Mailtraq Remote Format String SMTP Resource Consumption Vulnerability
It has been reported that Mailtraq does not reliably handle format strings in some SMTP protocol fields. This may cause a system to become unstable and crash, allowing a remote attacker to deny service to the system.
It has been reported that Mailtraq does not reliably handle format strings in some SMTP protocol fields. This may cause a system to become unstable and crash, allowing a remote attacker to deny service to the system.
Exploit / POC
Mailtraq Remote Format String SMTP Resource Consumption Vulnerability
The following example exploit strings have been made available:
@@%s%p%n
%s%p%n
The following example exploit strings have been made available:
@@%s%p%n
%s%p%n
Solution / Fix
Mailtraq Remote Format String SMTP Resource Consumption Vulnerability
Solution:
It has been reported that this issue is resolved in version 2.3.2.1419 of the software. This has not been confirmed by the vendor.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that this issue is resolved in version 2.3.2.1419 of the software. This has not been confirmed by the vendor.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.