CERT home
vulnerabilities & fixesevaluations & practicesresearch & analysistraining & education
homesearchFAQsite indexcontact
Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information
 

 View Notes By
Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric

Vulnerability Note VU#445313

602pro Lan Suite 2003 buffer overflow vulnerability

Overview

602pro Lan Suite 2003 contains a buffer overflow vulnerability that may allow an attacker to execute code.

I. Description

602pro Lan Suite 2003 is a mail, firewall and proxy server that runs on the Microsoft Windows operating system.

The 602pro Lan Suite 2003 SMTP server contains a buffer overflow vulnerability. To exploit this vulnerability, an attacker would need to send a specially crafted email through the SMTP component of a vulnerable server.

II. Impact

A remote unauthenticated attacker may be able to execute arbitrary code, or create a denial-of-service condition.

III. Solution

Upgrade

The vendor has stated that this issue is addressed in 602 LAN Suite 2004.

Restrict access

Disabling or restricting access to the SMTP server will mitigate this vulnerability. See the 602pro Lan Suite 2003 administrator manual for details on how to configure the SMTP service.

Systems Affected

VendorStatusDate Updated
Software602, Inc.Vulnerable27-Jun-2007

References


http://download.software602.com/pdf/lns/2003/ls2003_manual.pdf
http://www.software602.com/products/ls/
http://secunia.com/advisories/25429/

Credit

Thanks to David Barker of Electrosonics for reporting this vulnerability.

This document was written by Ryan Giobbi.

Other Information

Date Public06/12/2007
Date First Published06/27/2007 04:48:46 PM
Date Last Updated06/27/2007
CERT Advisory 
CVE Name 
Metric2.95
Document Revision19

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

Copyright 2007 Carnegie Mellon University