SLMail Buffer Overflow 'helo' Vulnerability

The POP Service of SLMail operates on tcp port 27. Issuing a 'helo' command followed by 855 to 2041 characters will cause the SLMail server to crash. An arbitrary command may be issued as a overflow exploit, although this is not discussed by the author of the post.


 

Privacy Statement
Copyright 2010, SecurityFocus