vendor:
EServ
by:
Andrew Lewis aka. Wizdumb [MDMA]
7.5
CVSS
HIGH
Heap Buffer Overflow
119
CWE
Product Name: EServ
Affected Version From: EType EServ <= 2.9.2
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: o:etype:eserv
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2000
EType EServ Heap Buffer Overflow
EType EServ is a combination mail, news, HTTP, FTP, and proxy server. The logging mechanism in EType EServ is vulnerable to a heap buffer overflow that could allow remote attackers to execute arbitrary code on the server. The overflow occurs when a MKD command with an unusually long argument is sent to the FTP Server port.
Mitigation:
Upgrade to the latest version of EType EServ.