vendor:
MailCarrier
by:
Patrick Webster
9
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: MailCarrier
Affected Version From: 2.51
Affected Version To: 2.51
Patch Exists: NO
Related CWE: CVE-2004-1638
CPE: a:mailcarrier:mailcarrier:2.51
Platforms Tested: Windows
2004
TABS MailCarrier v2.51 SMTP EHLO Overflow
This module exploits the MailCarrier v2.51 suite SMTP service. The stack is overwritten when sending an overly long EHLO command.
Mitigation:
Apply the latest patch or upgrade to a newer version of the software.