OSVDB ID: 12130

Title: CMailServer download.asp urlOfAttach Variable Remote Overflow

Info

Disclosure

Nov 24, 2004

Discovery

Nov 12, 2004

Dates

Exploit

Unknown

Solution

Unknown

Description

A remote overflow exists in CMailServer. The CMailServer uses an unsafe sprintf call resulting in a buffer overflow when handling an overly long filename in urlOfAttach. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 5.2.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Youngzsoft

CMailServer

5.2

References

Credit

  • Tan Chew Keong - vulnBrand New Doo Doosecunia.com - Secunia Research


Direct URL: http://osvdb.org/36218