Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Netwin CWMail Buffer Overflow Vulnerability

CWMail is a web based email system by Netwin. CWMail enables all email transactions to be done via web browser.

An issue has been reported in CWMail which could allow a user to initiate a buffer overflow.

Reportedly, CWMail does not properly handle large amounts of character sequences in the 'item=' parameter, this could cause a buffer overflow to occur. This overflow could overwrite stack variables, including the return address, and be used to execute arbitrary code.







 

Privacy Statement
Copyright 2008, SecurityFocus