InterScan VirusWall Long HELO Buffer Overflow Vulnerability

There is a buffer overflow in the HELO command of the smtp gateway which ships as part of the VirusWall product. This buffer overflow could be used to launch arbitrary code on the vulnerable server.

This issue was patched by InterScan, however even with the patch it is possible to cause a DoS of the mail server software by sending between 4075 and 4090 characters.


 

Privacy Statement
Copyright 2010, SecurityFocus