Vulnerability Note VU#619982
Zone Labs desktop security products fail to properly validate RCPT TO command argument
Overview
Zone Labs desktop security products contains a buffer overflow in the code that processes the RCPT TO command argument. This could allow an attacker to execute arbitrary code with SYSTEM privileges.
Description
Zone Labs offers a suite of desktop security products. These products provide a feature that allows incoming and outgoing e-mail messages to be analyzed for malicious content. There is a buffer overflow vulnerability in the component responsible for processing the RCPT TO command argument. By supplying an overly long value to the RCPT TO command, an attacker could execute arbitrary code with SYSTEM privileges. This vulnerability could be exploited remotely if an attacker could cause the victim's system to send a crafted outgoing message. |
Impact
An attacker could execute arbitrary code with SYSTEM privileges. |
Solution
Upgrade According to Zone Labs Security Advisory:
To update your Zone Labs client product:
2. In the Check for Updates area, choose an update option.
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Zone Alarm | Affected | - | 24 Feb 2004 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.eeye.com/html/Research/Advisories/AD20040219.html
- http://www.eeye.com/html/Research/Upcoming/20040213-2.html
- http://download.zonelabs.com/bin/free/securityAlert/8.html
- http://secunia.com/advisories/10921/
Credit
This vulnerability was reported by eEye Digital Security.
This document was written by Damon Morda.
Other Information
- CVE IDs: Unknown
- Date Public: 13 Feb 2004
- Date First Published: 24 Feb 2004
- Date Last Updated: 24 Feb 2004
- Severity Metric: 10.94
- Document Revision: 18
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.