vendor:
MailCarrier
by:
Dino Covotsos - Telspace Systems
7.5
CVSS
HIGH
Remote Buffer Overflow
Buffer Overflow
CWE
Product Name: MailCarrier
Affected Version From: 2.51
Affected Version To: 2.51
Patch Exists: NO
Related CWE: TBC from Mitre
CPE: N.A
Platforms Tested: Windows XP Prof SP3 ENG x86
2019
MailCarrier 2.51 – Remote Buffer Overflow in “USER” command(POP3)
This exploit allows an attacker to remotely trigger a buffer overflow vulnerability in the "USER" command of MailCarrier 2.51 POP3 server. By sending a specially crafted request to the server, an attacker can overwrite the EIP register and gain control of the execution flow, potentially allowing for remote code execution.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability.