A remote overflow exists in ZoneAlarm. The 'vsmon.exe' program fails to perform proper bounds checking resulting in a buffer overflow. By specifying a overly long argument in the RCPT TO command, a remote attacker can cause arbitrary code execution with SYSTEM privileges resulting in a loss of integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
ZoneAlarm, ZoneAlarm Pro, ZoneAlarm Plus users should upgrade to 4.5.594.000 or later. Integrity 4.0 users should upgrade to 4.0.146.046 or later. Integrity 4.5 users should upgrade to 4.5.085 or later. The versions have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.