CSM Mailserver HELO Buffer Overflow Vulnerability
BID:895
Info
CSM Mailserver HELO Buffer Overflow Vulnerability
| Bugtraq ID: | 895 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 29 1999 12:00AM |
| Updated: | Dec 29 1999 12:00AM |
| Credit: | Discovered and publicized by USSR Labs on December 29, 1999. |
| Vulnerable: |
CSM Mailserver 2000.8 .A |
| Not Vulnerable: | |
Discussion
CSM Mailserver HELO Buffer Overflow Vulnerability
The CSM Mailserver has an unchecked buffer in the code that handles the HELO command, and can be crashed by submitting an argument of over 12000 bytes to a HELO command.
The CSM Mailserver has an unchecked buffer in the code that handles the HELO command, and can be crashed by submitting an argument of over 12000 bytes to a HELO command.
Exploit / POC
CSM Mailserver HELO Buffer Overflow Vulnerability
see discussion
see discussion
Solution / Fix
CSM Mailserver HELO Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
CSM Mailserver HELO Buffer Overflow Vulnerability
References:
References: