Vulnerabilities > CVE-2005-2943 - Local Buffer Overflow vulnerability in XMail

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
davide-libenzi
nessus
exploit available

Summary

Stack-based buffer overflow in sendmail in XMail before 1.22 allows remote attackers to execute arbitrary code via a long -t command line option.

Exploit-Db

descriptionXMail 1.21 (-t Command Line Option) Local Root Buffer Overflow Exploit. CVE-2005-2943. Local exploit for linux platform
idEDB-ID:1267
last seen2016-01-31
modified2005-10-20
published2005-10-20
reporterqaaz
sourcehttps://www.exploit-db.com/download/1267/
titleXMail 1.21 -t Command Line Option Local Root Buffer Overflow Exploit

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-902.NASL
    descriptionA buffer overflow has been discovered in the sendmail program of xmail, an advanced, fast and reliable ESMTP/POP3 mail server that could lead to the execution of arbitrary code with group mail privileges.
    last seen2020-06-01
    modified2020-06-02
    plugin id22768
    published2006-10-14
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/22768
    titleDebian DSA-902-1 : xmail - buffer overflow
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200512-05.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200512-05 (Xmail: Privilege escalation through sendmail) iDEFENSE reported that the AddressFromAtPtr function in the sendmail program fails to check bounds on arguments passed from other functions, and as a result an exploitable stack overflow condition occurs when specifying the
    last seen2020-06-01
    modified2020-06-02
    plugin id20314
    published2005-12-15
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/20314
    titleGLSA-200512-05 : Xmail: Privilege escalation through sendmail