vendor:
AL-Mail32
by:
UNYUN
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: AL-Mail32
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: YES
Related CWE: N/A
CPE: a:al-software:al-mail32
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows98
1999
ALMail32 POP3 Client Buffer Overflow Vulnerability
The ALMail32 POP3 client contains unchecked buffers in the header parsing code. An abnormally long FROM: or TO: field in the header of an incoming email will overwrite the buffer and allow arbitrary code to be executed.
Mitigation:
Upgrade to the latest version of ALMail32 POP3 Client