PT-2003-1472 · Slmail · Slmail
David Litchfield
+1
·
Published
2003-05-08
·
Updated
2021-02-24
·
CVE-2003-0264
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
SLMail version 5.1.0.4420
Description:
The issue allows remote attackers to execute arbitrary code due to multiple buffer overflows. This can be achieved through various means, including a long EHLO argument to slmail.exe, a long XTRN argument to slmail.exe, a long string to POPPASSWD, or a long password to the POP3 server.
Recommendations:
For SLMail version 5.1.0.4420, consider restricting access to the slmail.exe and POP3 server until a patch is available. As a temporary workaround, limit the length of input arguments and strings to prevent buffer overflows. Avoid using long passwords or strings in the POPPASSWD and POP3 server.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Slmail