vendor:
Pegasus Mail Client
by:
Francis Provencher
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Pegasus Mail Client
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Professional SP2
2009
Pegasus Mail Client Remote BoF
Pegasus Mail is a mail client suitable for single or multiple users on stand-alone computers and for internal and Internet mail on local area networks. It has minimal system requirements compared with competing products, for instance the installed program (excluding mailboxes) for version 4.51 requires only around 13.5 MB of hard drive space. A key feature of Pegasus Mail is that it does not use the HTML layout engine that is installed with every Microsoft operating system since 1997, making it immune to security exploits. This vulnerability is a remote buffer overflow exploit which can be used to cause a denial of service.
Mitigation:
Ensure that the latest version of Pegasus Mail is installed and that all security patches are applied.