vendor:
Elm
by:
xfer
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Elm
Affected Version From: 2.5 PL3
Affected Version To: 2.5 PL3
Patch Exists: YES
Related CWE: N/A
CPE: a:elm_project:elm
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux Slackware 3.6, 4.0, 7.0
2000
Buffer overflow vulnerabilities in elm (Electronic Mail for Unix)
Buffer overflow vulnerabilities exist in elm (Electronic Mail for Unix). A proof-of-concept exploit was published by xfer of Buffer0verfl0w Security in 2000. The exploit uses a setregid + generic shell code and is tested under Linux Slackware 3.6, 4.0, 7.0. The exploit requires the user to play with the offset to gain access.
Mitigation:
Upgrade to the latest version of elm (Electronic Mail for Unix).