Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

RipMime Mime_Header Long Filename Buffer Overflow Vulnerability

ripMime ships with the the Inflex e-mail virus scanning utility. It also is distributed with the commercial version of XaMime, which is the commercial version of Inflex. Inflex/XaMime/ripMime will run on most Linux and Unix variants.

A locally exploitable buffer overflow has been discovered in ripMime's handling of filenames. Passing an excessively long filename (2079+ characters) through the appropriate command line switches causes the EIP to be overwritten. An attacker may exploit this situation to execute arbitrary code, potentially resulting in an elevation of privileges.







 

Privacy Statement
Copyright 2008, SecurityFocus