Vulnerability Note VU#445313

602pro Lan Suite 2003 buffer overflow vulnerability

Original Release date: 27 Jun 2007 | Last revised: 27 Jun 2007

Overview

602pro Lan Suite 2003 contains a buffer overflow vulnerability that may allow an attacker to execute code.

Description

602pro Lan Suite 2003 is a mail, firewall and proxy server that runs on the Microsoft Windows operating system.

The 602pro Lan Suite 2003 SMTP server contains a buffer overflow vulnerability. To exploit this vulnerability, an attacker would need to send a specially crafted email through the SMTP component of a vulnerable server.

Impact

A remote unauthenticated attacker may be able to execute arbitrary code, or create a denial-of-service condition.

Solution

Upgrade
The vendor has stated that this issue is addressed in 602 LAN Suite 2004.


Restrict access

Disabling or restricting access to the SMTP server will mitigate this vulnerability. See the 602pro Lan Suite 2003 administrator manual for details on how to configure the SMTP service.

Systems Affected (Learn More)

VendorStatusDate NotifiedDate Updated
Software602, Inc.Affected-27 Jun 2007
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A N/A

References

Credit

Thanks to David Barker of Electrosonics for reporting this vulnerability.

This document was written by Ryan Giobbi.

Other Information

  • CVE IDs: Unknown
  • Date Public: 12 Jun 2007
  • Date First Published: 27 Jun 2007
  • Date Last Updated: 27 Jun 2007
  • Severity Metric: 2.95
  • Document Revision: 19

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.