SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#841132

LISTSERV contains multiple buffer overflow vulnerabilities in the WA CGI script

Overview

Several buffer overflow vulnerabilities have been discovered in LISTSERV. These vulnerabilities could allow a remote attacker to execute arbitrary code on an affected system.

I. Description

L-Soft's LISTSERV is an email list management software package. It includes a Web Archive and Administration (WA) interface that allows users to browse and search list archives, and list owners and site maintainers to perform a number of management tasks. Several buffer overflow errors were discovered in the WA CGI component. These vulnerabilities are reported to affect LISTSERV versions 14.3 and 14.4, including LISTSERV Lite and HPO on all supported platforms. The specific nature of the underlying vulnerabilities is unknown at this time, however the reporter has stated that additional technical details will be publicly released on 2006-06-03.

II. Impact

A remote attacker may be able to execute code of their choosing with the permissions of the WA CGI program.

III. Solution

Upgrade

L-Soft has released version 14.5 of LISTSERV and LISTSERV Lite that contains a fix for these vulnerabilities. For more information please see the "WA Security Alert" featured in the software release notes. Users of these products are strongly urged to upgrade to this fixed version of the software.

Systems Affected

No Information Available

References


http://www.ngssoftware.com/advisories/listserv_3.txt
http://secunia.com/advisories/19106/
http://www.lsoft.com/manuals/1.8e/relnotes/LISTSERV14.5-Release-Notes.html#wasecurityalert

Credit

Peter Winter-Smith of Next Generation Security Software Research reported this vulnerability.

This document was written by Chad R Dougherty.

Other Information

Date Public:2006-03-03
Date First Published:2006-03-09
Date Last Updated:2006-03-09
CERT Advisory: 
CVE-ID(s):CVE-2006-1044
NVD-ID(s):CVE-2006-1044
US-CERT Technical Alerts: 
Metric:18.28
Document Revision:10

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader