602Pro Lan Suite 2003 Remote Email Message Buffer Overflow Vulnerability

TITLE: 602Pro Lan Suite 2003 Remote Email Message Buffer Overflow Vulnerability
CLASS: Boundary Condition Error
CVE:
REMOTE: Yes
LOCAL: No
PUBLISHED: Jun 12 2007 12:00AM
UPDATE: Jun 12 2007 12:00AM
CREDIT: David Barker of Electrosonics, Inc. discovered this issue.
VULNERABLE:

602 Software 602 Pro Lan Suite 2003
NOT VULNERABLE:
602 Software 602 Pro Lan Suite 2004

Vai alla pagina originale su Security Focus

Discussion

602Pro Lan Suite 2003 is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data.

Successfully exploiting this issue may allow remote attackers to execute arbitrary machine code in the context of the vulnerable application; failed exploit attempts will likely crash the application. This may facilitate the remote compromise of affected computers.

Exploit

Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:vuldb@securityfocus.com.

Solution

Solution:
The vendor provides a newer version of the software which is reportedly not vulnerable to this issue.

References

References:

PhpLog

BNLug Benevento Linux Users Group