PT-2002-1062 · Libesmtp · Libesmtp

Published

2002-09-10

·

Updated

2008-09-05

·

CVE-2002-1090

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libesmtp versions prior to 0.8.11
Description The issue allows a remote SMTP server to execute arbitrary code or cause a denial of service via long server responses due to a buffer overflow in the read smtp response function of protocol.c. This can lead to a disruption in confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations For versions prior to 0.8.11, update to version 0.8.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the read smtp response function in protocol.c to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08149
BDU:2015-08150
CVE-2002-1090

Affected Products

Libesmtp