Seattle Lab Software SLWebMail Multiple Buffer Overflow Vulnerabilities
BID:9808
Info
Seattle Lab Software SLWebMail Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 9808 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0357 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2004 12:00AM |
| Updated: | Jul 12 2009 03:06AM |
| Credit: | The disclosure of these issues has been credited to NGSSoftware design <http://www.ngssoftware.com/>. |
| Vulnerable: |
Seattle Lab Software SLWebMail BVRP Software SLWebMail 3 |
| Not Vulnerable: | |
Discussion
Seattle Lab Software SLWebMail Multiple Buffer Overflow Vulnerabilities
It has been reported that SLWebMail is prone to multiple buffer overflow vulnerabilities that may allow an attacker gain unauthorized access. The vulnerabilities are reported to exist in user.dll, loadpageadmin.dll and loadpageuser.dll.
SLWebMail shipped with SLMail Pro versions 2.0.9 and prior is reported to be affected by these issues.
It has been reported that SLWebMail is prone to multiple buffer overflow vulnerabilities that may allow an attacker gain unauthorized access. The vulnerabilities are reported to exist in user.dll, loadpageadmin.dll and loadpageuser.dll.
SLWebMail shipped with SLMail Pro versions 2.0.9 and prior is reported to be affected by these issues.
Exploit / POC
Seattle Lab Software SLWebMail Multiple Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Seattle Lab Software SLWebMail Multiple Buffer Overflow Vulnerabilities
Solution:
The vendor has released Security Patch 2.0.14 to address these issues:
BVRP Software SLWebMail 3
Seattle Lab Software SLWebMail
Solution:
The vendor has released Security Patch 2.0.14 to address these issues:
BVRP Software SLWebMail 3
-
Seattle Lab Software Security Patch 2.0.14
http://216.26.170.92/Download/webfiles/Patches/SLMailPro_Patch_2.0.14. exe
Seattle Lab Software SLWebMail
-
Seattle Lab Software Security Patch 2.0.14
http://216.26.170.92/Download/webfiles/Patches/SLMailPro_Patch_2.0.14. exe
References
Seattle Lab Software SLWebMail Multiple Buffer Overflow Vulnerabilities
References:
References:
- BVRP Software (BVRP Software)
- SLWebMail Multiple Buffer Overflow Vulnerabilities (#NISR05022004b) ("NGSSoftware Insight Security Research"
)