E-MailClub Buffer Overflow Vulnerability
BID:801
Info
E-MailClub Buffer Overflow Vulnerability
| Bugtraq ID: | 801 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-1190 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 15 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | This vulnerability was found by the Shadow Penguin Team and posted to their Website on November 15, 1998. |
| Vulnerable: |
Admiral Systems EmailClub 1.0 .0.5 |
| Not Vulnerable: |
Admiral Systems EmailClub 1.0 .6 |
Discussion
E-MailClub Buffer Overflow Vulnerability
Certain versions of EmailClub, a mail server package by Admiral Systems Inc. are vulnerable to a remote buffer overflow. This overflow is exploitable via EmailClub's POP3 server which fails to perform proper bounds checking on the 'From:' header on incoming e-mail.
This overflow will lead to a complete compromise of the Windows 95/98 target machine. It may well also affect Windows NT installations in the same manner. It is unclear though if EmailClub run with ADMIN privileges under Windows NT installations.
Certain versions of EmailClub, a mail server package by Admiral Systems Inc. are vulnerable to a remote buffer overflow. This overflow is exploitable via EmailClub's POP3 server which fails to perform proper bounds checking on the 'From:' header on incoming e-mail.
This overflow will lead to a complete compromise of the Windows 95/98 target machine. It may well also affect Windows NT installations in the same manner. It is unclear though if EmailClub run with ADMIN privileges under Windows NT installations.
Exploit / POC
Solution / Fix
E-MailClub Buffer Overflow Vulnerability
Solution:
Patches for version 1.0.0.5, as well as an upgrade to version 1.0.0.6 which is not vulnerable to this issue, are available at:
http://email-club.admiral.co.jp/Release/EMC-Note.htm
(japanese only)
Solution:
Patches for version 1.0.0.5, as well as an upgrade to version 1.0.0.6 which is not vulnerable to this issue, are available at:
http://email-club.admiral.co.jp/Release/EMC-Note.htm
(japanese only)
References
E-MailClub Buffer Overflow Vulnerability
References:
References:
- eEye Digital Security Team Home Page (eEye)
- EmailClub Homepage (Japanese) (Admiral Systems Inc.)
- Penguin Toolbox #54: EmailClub (Shadow Penguin Security)