Get a Pentest and security assessment of your IT network.

Advisories

Zero Day Initiative Advisory 07-072

Vulnerabilities allow attackers to execute arbitrary code on vulnerable installations of Novell NetMail. User interaction is not required to exploit this vulnerability. The specific flaws exist in the AntiVirus agent which listens on a random high TCP port. The avirus.exe service protocol reads a user-supplied ASCII integer value as an argument to a memory allocation routine. The specified size is added to without any integer overflow checks and can therefore result in an under allocation. A subsequent memory copy operation can then corrupt the heap and eventually result in arbitrary code execution. Novell NetMail version 3.5.2 is affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/61676/ZDI-07-072.txt

Source: https://packetstormsecurity.com/files/61676/Zero-Day-Initiative-Advisory-07-072.html

Related posts
Advisories

CSIS2005-1.txt

Advisories

Secunia Security Advisory 17625

Advisories

Secunia Security Advisory 20411

Advisories

Secunia Security Advisory 23300