Ipswitch IMail Server/Collaboration Suite ActiveX控件多个缓冲区溢出漏洞

漏洞信息详情

Ipswitch IMail Server/Collaboration Suite ActiveX控件多个缓冲区溢出漏洞

漏洞简介

Ipswitch IMail Server是美国Ipswitch公司的一款运行于Microsoft Windows操作系统中的邮件服务器。

IMail Server所带一些ActiveX控件实现上存在缓冲区溢出漏洞,远程攻击者可能利用这些漏洞通过诱使用户访问恶意网页来控制用户客户端机器。

不安全的strcpy和wsprintf调用所导致的多个堆溢出和栈溢出可能允许代码执行。有漏洞控件的详细信息如下 :

ProgID: IMAILAPILib.IMailServer

CLSID: 302397C2-8501-11D4-8D29-00010245C51E

targetFile: C:\Program Files\Ipswitch\IMail\IMailAPI.dll

memberName: WebConnect

memberName: Connect

ProgID: IMAILAPILib.IMailLDAPService

CLSID: 889558D4-CE9A-4A1B-B88A-AF7774A80E25

targetFile: C:\Program Files\Ipswitch\IMail\IMailAPI.dll

memberName: Sync3

memberName: Init3

ProgID: IMAILAPILib.IMailUserCollection

CLSID: 302397D6-8501-11D4-8D29-00010245C51E

targetFile: C:\Program Files\Ipswitch\IMail\IMailAPI.dll

memberName: SetReplyTo

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

ftp://ftp.ipswitch.com/Ipswitch/Product_Downloads/ICS_Standard.exe

参考网址

来源: doc.powerdns.com

链接:http://doc.powerdns.com/powerdns-advisory-2008-01.html

来源: FEDORA

名称: FEDORA-2008-3036

链接:https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00224.html

来源: FEDORA

名称: FEDORA-2008-3010

链接:https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00198.html

来源: XF

名称: powerdns-dnscache-weak-security(41534)

链接:http://xforce.iss.net/xforce/xfdb/41534

来源: MISC

链接:http://www.trusteer.com/docs/powerdnsrecursor.html

来源: MISC

链接:http://www.trusteer.com/docs/PowerDNS_recursor_DNS_Cache_Poisoning.pdf

来源: BID

名称: 28517

链接:http://www.securityfocus.com/bid/28517

来源: BUGTRAQ

名称: 20080331 Paper by Amit Klein (Trusteer): “PowerDNS Recursor DNS Cache Poisoning [pharming]”

链接:http://www.securityfocus.com/archive/1/archive/1/490330/100/0/threaded

来源: VUPEN

名称: ADV-2008-1046

链接:http://www.frsirt.com/english/advisories/2008/1046/references

来源: DEBIAN

名称: DSA-1544

链接:http://www.debian.org/security/2008/dsa-1544

来源: GENTOO

名称: GLSA-200804-22

链接:http://security.gentoo.org/glsa/glsa-200804-22.xml

来源: SECUNIA

名称: 30581

链接:http://secunia.com/advisories/30581

来源: SECUNIA

名称: 29830

链接:http://secunia.com/advisories/29830

来源: SECUNIA

名称: 29764

链接:http://secunia.com/advisories/29764

来源: SECUNIA

名称: 29737

链接:http://secunia.com/advisories/29737

来源: SECUNIA

名称: 29584

链接:http://secunia.com/advisories/29584

来源: SUSE

名称: SUSE-SR:2008:012

链接:http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html

来源: CONFIRM

链接:http://doc.powerdns.com/changelog.html

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享