vendor:
elm email client
by:
Ulf Harnhammar
7,5
CVSS
HIGH
Buffer Overflow
120 (Buffer Copy without Checking Size of Input)
CWE
Product Name: elm email client
Affected Version From: 2.5.8
Affected Version To: 2.5.8
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Redhat
2005
Exploit for elm email client < 2.5.8 overflow in Expires field
Exploit code for the bug posted by Ulf Harnhammar (metaurtelia.com) which is a buffer overflow vulnerability in elm email client < 2.5.8 in Expires field. The exploit code adds an exploit buffer to the email and sends it using the elm command. The exploit buffer contains the address of the system() function, the address of the string to be executed and the address of the exit() function.
Mitigation:
Upgrade to the latest version of elm email client.