Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2001-1355

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2001-1355
Last Modified 05 Sep 2008 04:26:20
Published 20 Jul 2001 12:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2001-1355

Summary

Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitrary code via long arguments to (1) the -del command or (2) the -lookup command.

Vulnerable Systems

Application

  • Netwin Dmail 2.5d

  • Netwin Dmail 2.7

  • Netwin Dmail 2.7q

  • Netwin Dmail 2.7r

  • Netwin Dmail 2.8e

  • Netwin Dmail 2.8f

  • Netwin Dmail 2.8g

  • Netwin Dmail 2.8h

  • Netwin Dmail 2.8i

  • Netwin Surgeftp 1.0b

  • Netwin Surgeftp 2.0a

  • Netwin Surgeftp 2.0b


References

XF - netwin-nwauth-bo(6865)

BID - 3077

BUGTRAQ - 20010720 NetWin Authentication Module 3.0b password storage vulnerabilities / buffer overflows


Last Updated: 27 May 2016 10:36:38