Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

MMMail Remote SysLog Format String Vulnerability

mmmail is a freely available, open source mail software package. It was written originally by Matthew Mondor, and is available for the Linux operating system.

Due to improper use of the syslog call, a problem exists which could make the execution of arbitrary code possible. A syslog call in the program which logs user-supplied information could be exploited to print to specified places in memory, including potentially overwriting the return address of a function and executing arbitrary code.







 

Privacy Statement
Copyright 2008, SecurityFocus