lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20070502182539.mbsm1or3kock408o@webmail.skilltube.com>
Date: Wed,  2 May 2007 18:25:39 +0200
From: "skillTube.com" <lists73@...lltube.com>
To: bugtraq@...urityfocus.com
Subject: Vulnerability in InterVations' MailCopa

While developing one of our advanced security training movies, we
identified an exploitable vulnerability in the latest release of
InterVetions' MailCopa. Successful exploitation of this vulnerability
allows an attacker to execute arbitrary code in the context of the
user executing MailCopa. In a web-based attack scenario, an attacker
can insert a link in the following way:

<a href="mailto:test@...mple.com?subject=aaaaaaaaaaaa ... aaaaaaaaaaaaa">

If the user can be tricked into clicking on such a malicious link, an
overflow occurs, leading to code execution on the victim's system.


Countermeasures:
The vendor was informed on April 30, 2007 and published a patched
version just a few hours later. Amazing response time!


Credits:
skilltube.com

If you are interested in learning more about vulnerability research
and exploitation techniques, check out our advanced security training
movies on www.skillTube.com.




Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ