Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-1055
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-1055

Description:
Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in the page parameter.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/40833

ST
  1019500

SREASON
  http://securityreason.com/securityalert/3705

SAID
  Secunia Advisory: SA29137
  Secunia Advisory: SA29105

MISC
  http://aluigi.altervista.org/adv/surgemailz-adv.txt

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/488741/100/0/threaded

BID
  27990


Return to the previous page.