|
602Pro LAN SUITE 2003 Email Message Processing Buffer Overflow
|
|
Secunia Advisory:
|
SA25429
|
|
|
Release Date:
|
2007-06-12
|
|
Last Update:
|
2007-06-28
|
|
Popularity:
|
5,631 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Unpatched
|
|
| Software: | 602Pro LAN SUITE 2003
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2007-3203
|
|
Description: David Barker has discovered a vulnerability in LAN SUITE 2003, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a boundary error within smtpdll.dll when processing queued email messages with overly long email addresses. This can be exploited to cause a stack-based buffer overflow by e.g. sending an email message containing an overly long (greater than 260 bytes), specially crafted email address through the application's SMTP service.
Successful exploitation allows execution of arbitrary code.
The vulnerability is confirmed in 602Pro LAN SUITE 2003 build 2003.0.03.0828. Other versions may also be affected.
Solution: According to the vendor, a patch will not be issued. Instead, the vendor encourages users to upgrade to 602LAN SUITE 2004.
http://www.software602.com/download/
Provided and/or discovered by: David Barker, Electrosonics, Inc.
Changelog: 2007-06-15: Added CVE reference.
2007-06-28: Added link to US-CERT.
Other References: US-CERT VU#445313:
http://www.kb.cert.org/vuls/id/445313
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|