7.5
CVSSv2

CVE-2005-2943

Published: 13/10/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in sendmail in XMail prior to 1.22 allows remote malicious users to execute arbitrary code via a long -t command line option.

Vulnerable Product Search on Vulmon Subscribe to Product

davide libenzi xmail 1.16

davide libenzi xmail 1.17

davide libenzi xmail 1.4

davide libenzi xmail 1.5

davide libenzi xmail 1.11

davide libenzi xmail 1.12

davide libenzi xmail 1.2

davide libenzi xmail 1.20

davide libenzi xmail 1.8

davide libenzi xmail 1.9

davide libenzi xmail 1.14

davide libenzi xmail 1.15

davide libenzi xmail 1.21

davide libenzi xmail 1.3

davide libenzi xmail 1.0

davide libenzi xmail 1.1

davide libenzi xmail 1.10

davide libenzi xmail 1.18

davide libenzi xmail 1.19

davide libenzi xmail 1.6

davide libenzi xmail 1.7

Exploits

/* * XMail 121 'sendmail' local exploit (ret-into-libc) * Yields uid root || gid mail * By qaaz [at] centrum [dot] cz, 2005 */ #include <stdioh> #include <stdlibh> #include <unistdh> #include <stringh> #include <signalh> #include <sys/typesh> #include <sys/waith> #include <sys/selecth> #def ...