vendor:
CMailServer
by:
m00 security
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: CMailServer
Affected Version From: CMailServer 3.30
Affected Version To: Not provided
Patch Exists: NO
Related CWE: Not provided
CPE: Not provided
Platforms Tested: Windows 2000 SP3 English
Not provided
CMailServer Buffer Overflow
CMailServer is vulnerable to a buffer overflow condition. It does not perform proper bounds checking on the USER argument, allowing a remote attacker to execute arbitrary code on the system. This exploit allows for denial of service or the creation of a bind shell on port 61200. It has been tested on Windows 2000 SP3 English.
Mitigation:
Apply the vendor's patch or update to a non-vulnerable version of CMailServer. Disable or restrict access to the affected service if a patch or update is not available.