vendor:
ListProc
by:
kokaninATdtors.net
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: ListProc
Affected Version From: ListProc 8.2.09
Affected Version To: ListProc 8.2.09
Patch Exists: YES
Related CWE: N/A
CPE: listproc
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD 4.8-RELEASE
2003
ListProc catmail Buffer Overflow Vulnerability
ListProc catmail has been reported prone to a buffer overflow vulnerability when handling a ULISTPROC_UMASK environment variable of excessive length. The issue is likely due to a lack of sufficient bounds checking performed when copying the contents of the ULISTPROC_UMASK environment variable into an internal memory buffer. Ultimately an attacker may exploit this vulnerability to execute arbitrary operation codes. Code execution would occur in the context of the ListProc catmail application, typically root.
Mitigation:
Ensure that the ULISTPROC_UMASK environment variable is not set to an excessive length.