ID

VAR-200212-0158


CVE

CVE-2002-1985


TITLE

Incognito Systems ISMTP Gateway Remote buffer overflow vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200212-822

DESCRIPTION

iSMTP 5.0.1 allows remote attackers to cause a denial of service via a long "MAIL FROM" command, possibly triggering a buffer overflow. A buffer overflow vulnerability has been reported for iSMTP Gateway. The vulnerability occurs due to inappropriate bounds checking when processing user-supplied input. An attacker can exploit this vulnerability by sending an overly long command to the vulnerable system. When the system receives this input it will crash. It may be possible that code execution may be possible, however, this has not been confirmed. iSMTP Gateway is a mail gateway software developed by Incognito System, running on the Banyan VINES operating system. Carefully crafted submission data may execute arbitrary commands with the privileges of the iSMTP process, although this has not been proven

Trust: 1.26

sources: NVD: CVE-2002-1985 // BID: 6151 // VULHUB: VHN-6368

AFFECTED PRODUCTS

vendor:incognitomodel:ismtp gatewayscope:eqversion:5.0.1

Trust: 1.6

vendor:incognitomodel:software inc ismtp gatewayscope:eqversion:5.0.1

Trust: 0.3

sources: BID: 6151 // CNNVD: CNNVD-200212-822 // NVD: CVE-2002-1985

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1985
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200212-822
value: MEDIUM

Trust: 0.6

VULHUB: VHN-6368
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2002-1985
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-6368
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-6368 // CNNVD: CNNVD-200212-822 // NVD: CVE-2002-1985

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1985

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200212-822

TYPE

Boundary Condition Error

Trust: 0.9

sources: BID: 6151 // CNNVD: CNNVD-200212-822

EXTERNAL IDS

db:BIDid:6151

Trust: 2.0

db:NVDid:CVE-2002-1985

Trust: 1.7

db:CNNVDid:CNNVD-200212-822

Trust: 0.7

db:NSFOCUSid:3817

Trust: 0.6

db:BUGTRAQid:20021111 BUFFER OVERFLOW IN ISMTP GATEWAY

Trust: 0.6

db:XFid:10577

Trust: 0.6

db:VULHUBid:VHN-6368

Trust: 0.1

sources: VULHUB: VHN-6368 // BID: 6151 // CNNVD: CNNVD-200212-822 // NVD: CVE-2002-1985

REFERENCES

url:http://www.securityfocus.com/bid/6151

Trust: 1.7

url:http://online.securityfocus.com/archive/1/299232

Trust: 1.7

url:http://www.nii.co.in/vuln/ismtp.html

Trust: 1.7

url:http://www.iss.net/security_center/static/10577.php

Trust: 1.7

url:http://www.nsfocus.net/vulndb/3817

Trust: 0.6

url:http://www.incognito.com/

Trust: 0.3

url:/archive/1/299232

Trust: 0.3

sources: VULHUB: VHN-6368 // BID: 6151 // CNNVD: CNNVD-200212-822 // NVD: CVE-2002-1985

CREDITS

K. K. Mookhey※ cto@nii.co.in

Trust: 0.6

sources: CNNVD: CNNVD-200212-822

SOURCES

db:VULHUBid:VHN-6368
db:BIDid:6151
db:CNNVDid:CNNVD-200212-822
db:NVDid:CVE-2002-1985

LAST UPDATE DATE

2024-08-14T15:41:00.839000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-6368date:2008-09-05T00:00:00
db:BIDid:6151date:2002-11-11T00:00:00
db:CNNVDid:CNNVD-200212-822date:2005-10-20T00:00:00
db:NVDid:CVE-2002-1985date:2008-09-05T20:32:01.730

SOURCES RELEASE DATE

db:VULHUBid:VHN-6368date:2002-12-31T00:00:00
db:BIDid:6151date:2002-11-11T00:00:00
db:CNNVDid:CNNVD-200212-822date:2002-11-11T00:00:00
db:NVDid:CVE-2002-1985date:2002-12-31T05:00:00