Description
Multiple buffer overflows in SLWebMail 3 on Windows systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long Language parameter to showlogin.dll, (2) a long CompanyID parameter to recman.dll, (3) a long CompanyID parameter to admin.dll, or (4) a long CompanyID parameter to globallogin.dll.
Affected products
- BVRP Software / slwebmail3.0 – 3.0
References
- MAILING_LISThttp://marc.info/?l=bugtraq&m=105232436210273&w=2
- VENDOR_ADVISORYhttp://www.nextgenss.com/advisories/slwebmail-vulns.txt
- MAILING_LISThttp://marc.info/?l=ntbugtraq&m=105233363721919&w=2