qwik-smtpd format string

看板Bugtraq作者時間19年前 (2007/02/21 08:33), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Advisory : H0tTurk- Product : qwik-smtpd (latest version). Vendor : http://qwikmail.sourceforge.net/ Bug : format string vulnerability Vendor Status : Released Patch. http://qwikmail.sourceforge.net/smtpd/qwik-smtpd-0.3.patch ------------------------------------------------------------------------------------------------------------ It is an SMTP (mail) server that supports SMTP and ESMTP. Once finished, it will be very secure, hopefully with the same reputation as qmail. ------------------------------------------------- I found format string bug in Qwik-SMTP daemon. See this: File: qwik-smtpd.c sprintf(Received,"Received: from %s (TURK %s) (%s) by %s with SMTP; %s\n", clientHost, clientHelo, clientIP, localHost, timebuf); .... else { fprintf(fpout,Received); ..... As you can see, bug found in main() function. This type is REMOTE. We don't want to release an exploit to avoid kids usage. Spc Thx: Drmaxvirus,Gencturk,İlkerkandemir,TiT,LuciferCihan,madconfig,tr-zindan,Theghost,SAWTURK,Ambassador,RidvanCihan,Crackers_Child,Kurtefendy,And Ayyildiz Vip TiM User,Soldiers
文章代碼(AID): #15svDU00 (Bugtraq)