Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string vulnerability that allows remote code execution.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/34217 | vdb entry |
http://osvdb.org/35891 | vdb entry |
http://www.vupen.com/english/advisories/2007/1755 | vdb entry vendor advisory |
http://www.netwinsite.com/surgemail/help/updates.htm | patch |
http://www.securityfocus.com/bid/23908 | patch vdb entry |
http://secunia.com/advisories/25207 | patch vendor advisory third party advisory |