PT-2003-1488 · Unknown · Cmailserver

Dennis Rand

·

Published

2003-05-14

·

Updated

2017-07-11

·

CVE-2003-0280

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: CMailServer version 4.0.2003.03.27
Description: The issue concerns multiple buffer overflows in the SMTP Service for ESMTP, allowing remote attackers to execute arbitrary code. This can be achieved by sending long commands, specifically the MAIL FROM or RCPT TO commands.
Recommendations: For CMailServer version 4.0.2003.03.27, consider restricting the length of MAIL FROM and RCPT TO commands to prevent buffer overflows until a patch is available. Additionally, limiting access to the SMTP Service can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0280

Affected Products

Cmailserver