Vulnerability Note VU#445313
602pro Lan Suite 2003 buffer overflow vulnerability
Overview
602pro Lan Suite 2003 contains a buffer overflow vulnerability that may allow an attacker to execute code.
Description
602pro Lan Suite 2003 is a mail, firewall and proxy server that runs on the Microsoft Windows operating system. The 602pro Lan Suite 2003 SMTP server contains a buffer overflow vulnerability. To exploit this vulnerability, an attacker would need to send a specially crafted email through the SMTP component of a vulnerable server. |
Impact
A remote unauthenticated attacker may be able to execute arbitrary code, or create a denial-of-service condition. |
Solution
Upgrade |
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Software602, Inc. | Affected | - | 27 Jun 2007 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://download.software602.com/pdf/lns/2003/ls2003_manual.pdf
- http://www.software602.com/products/ls/
- http://secunia.com/advisories/25429/
Credit
Thanks to David Barker of Electrosonics for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
- CVE IDs: Unknown
- Date Public: 12 Jun 2007
- Date First Published: 27 Jun 2007
- Date Last Updated: 27 Jun 2007
- Severity Metric: 2.95
- Document Revision: 19
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.