vendor:
Eudora WorldMail
by:
Tim Shelton
7.5
CVSS
HIGH
Buffer Overflow
Unknown
CWE
Product Name: Eudora WorldMail
Affected Version From: Eudora Qualcomm WorldMail 3.0 IMAPd Service 6.1.19.0
Affected Version To: Eudora Qualcomm WorldMail 3.0 IMAPd Service 6.1.19.0
Patch Exists: No
Related CWE: Unknown
CPE: Unknown
Platforms Tested:
Unknown
PRE AUTHENTICATION Eudora Qualcomm WorldMail 3.0 IMAPd Service 6.1.19.0 Overflow
SEH gets overwritten at 970 bytes in the LIST command. No space for shellcode, so 1st stage shellcode is used to jump back 768 bytes into the bindshell (2nd stage) shellcode.
Mitigation:
Unknown