|
Netwin CWMail Buffer Overflow Vulnerability
CWMail is a web based email system by Netwin. CWMail enables all email transactions to be done via web browser. An issue has been reported in CWMail which could allow a user to initiate a buffer overflow. Reportedly, CWMail does not properly handle large amounts of character sequences in the 'item=' parameter, this could cause a buffer overflow to occur. This overflow could overwrite stack variables, including the return address, and be used to execute arbitrary code. |
|
|
Privacy Statement |