vendor:
dSMTP - SMTP Mail Server
by:
cybertronic
7.5
CVSS
HIGH
Remote Root Format String Exploit
CWE
Product Name: dSMTP - SMTP Mail Server
Affected Version From: 3.1b
Affected Version To: 3.1b
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2005
dSMTP – SMTP Mail Server 3.1b Linux Remote Root Format String Exploit
This exploit targets the "xtellmail" command in dSMTP - SMTP Mail Server 3.1b on Linux. It uses a format string vulnerability to gain remote root access. The exploit sends a specially crafted packet to the server, overwriting the return address and executing shellcode to spawn a reverse shell. This allows the attacker to gain full control of the server.
Mitigation:
Upgrade to a patched version of dSMTP - SMTP Mail Server or apply any available security patches. Limit access to the affected service to trusted networks or IP addresses. Regularly monitor and update server software to protect against potential vulnerabilities.