Overview
602pro Lan Suite 2003 contains a buffer overflow vulnerability that may allow an attacker to execute code.
Description
602pro Lan Suite 2003 is a mail, firewall and proxy server that runs on the Microsoft Windows operating system. The 602pro Lan Suite 2003 SMTP server contains a buffer overflow vulnerability. To exploit this vulnerability, an attacker would need to send a specially crafted email through the SMTP component of a vulnerable server. |
Impact
A remote unauthenticated attacker may be able to execute arbitrary code, or create a denial-of-service condition. |
Solution
Upgrade |
|
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- |
| Temporal | 0 | E:ND/RL:ND/RC:ND |
| Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to David Barker of Electrosonics for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
| CVE IDs: | None |
| Severity Metric: | 2.95 |
| Date Public: | 2007-06-12 |
| Date First Published: | 2007-06-27 |
| Date Last Updated: | 2007-06-28 00:07 UTC |
| Document Revision: | 22 |