Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary commands via a long MAIL FROM mail header.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sniffit处理邮件头缓冲区溢出漏洞
Vulnerability Description
Sniffit是一个常用的sniffer工具。可运行在多种Unix/Linux平台上。 它存在一个缓冲区溢出漏洞,可能导致攻击者远程获取root权限。 Sniffit在使用"-L mail"参数处理窃听到的邮件头("mail from:"和"rcpto to:")的时候,会将它们拷贝到一个固定大小的buffer中,导致可能发生溢出问题:问题处在下列两个地方: if(strstr(workbuf1,"mail from")!=NULL) { char workbuf2[MTU]; strcpy(workbu
CVSS Information
N/A
Vulnerability Type
N/A