PT-2003-1488 · Unknown · Cmailserver
Dennis Rand
·
Published
2003-05-14
·
Updated
2017-07-11
·
CVE-2003-0280
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
CMailServer version 4.0.2003.03.27
Description:
The issue concerns multiple buffer overflows in the SMTP Service for ESMTP, allowing remote attackers to execute arbitrary code. This can be achieved by sending long commands, specifically the
MAIL FROM or RCPT TO commands.Recommendations:
For CMailServer version 4.0.2003.03.27, consider restricting the length of
MAIL FROM and RCPT TO commands to prevent buffer overflows until a patch is available. Additionally, limiting access to the SMTP Service can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cmailserver