Press CTRL-D to bookmark us
Welcome Guest Login / Register / Members
Search in  
Top Submit newsSubscribe
Communication | Computer Crime | Digital Audio, Video, Photo | General News | Hardware | Internet | Mobile | PDA | Security | Software | Vulnerability |


Previous articleBack to news listNext article
 

 Sponsored links

Want to become one of our authors and see your work published on ALLSeek.iNFO ?
 
 Fujitsu tsworks Attachment Expansion Buffer Overflow May Permit Remote Code Execution
Categorie: Vulnerability
Posted: 2003-11-12 by ReCall
Views: 397
Source: Click here
 
Current Rating: Not rated
Poor Best
 Details
Description: A buffer overflow vulnerability was reported in Fujitsu's tsworks e-mail client. A remote user can cause arbitrary code to be executed in certain cases.

Secure Net Service (SNS) warned that there is a buffer overflow vulnerability in tsworks that may allow a remote user to execute arbitrary code on the target system.

A remote user can reportedly send an e-mail message with an attachment that contains an "unusually long" string of characters to a target user. Then, when the target user attempts to invoke the "Expand the Attachment" function, the buffer overflow will be triggered, according to the report.

Hisayuki Shinmachi is credited with discovery.

The original SNS advisory is available at:

http://www.lac.co.jp/security/english/snsadv_e/70_e.html

Impact: A remote user can send an attachment that, when expanded by the target user, will execute arbitrary code on
the target user's computer. The code will run with the privileges of the target user.

Solution: The vendor has reportedly issued a fixed version (3.1), available at:


http://www.hnc.fujitsu.com/products/tsworks/update.html#ver3101
 
Syndication
Permalink Email this

The URI to TrackBack this entry is:
http://allseek.info/news/trackback.php?id=527

User comments (post your comments here)

Only registerd members can post comments and articles
 

Previous articleBack to news listNext article
 



InterJOB.su

SpyLOG Page Rank Checker
LAST QUERIES