vendor:
MailCarrier
by:
Dino Covotsos - Telspace Systems
9.3
CVSS
HIGH
SEH Remote Buffer Overflow
119
CWE
Product Name: MailCarrier
Affected Version From: 2.51
Affected Version To: 2.51
Patch Exists: YES
Related CWE: TBC from Mitre
CPE: a:tabslab:mailcarrier:2.51
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP Prof SP3 ENG x86
2019
MailCarrier 2.51 – SEH Remote Buffer Overflow in “LIST” command(POP3)
MailCarrier 2.51 is vulnerable to a SEH Remote Buffer Overflow in the "LIST" command of the POP3 protocol. By sending a specially crafted buffer, an attacker can overwrite the SEH handler and execute arbitrary code on the target machine.
Mitigation:
Upgrade to the latest version of MailCarrier 2.51 or apply the patch provided by the vendor.