vendor:
CMailServer
by:
Anonymous
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: CMailServer
Affected Version From: CMailServer 3.30
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 2000
2002
CMailServer Buffer Overflow Vulnerability
CMailServer is vulnerable to a buffer overflow condition. It does not perform proper bounds checking on the USER argument, allowing a remote attacker to execute arbitrary code on the vulnerable system. The issue has been reported in CMailServer 3.30, but other versions may also be affected. The exploit code provided in the text demonstrates the ability to execute arbitrary code on a Windows 2000 system.
Mitigation:
Apply patches or updates provided by the vendor. Upgrade to a non-vulnerable version of CMailServer.