CVE

Id
1921  
CVE No.
CVE-2000-0343  
Status
Candidate  
Description
Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary commands via a long MAIL FROM mail header.  
Phase
Proposed (20000518)  
Votes
ACCEPT(2) Cole, Levy | MODIFY(2) Christey, Frech | NOOP(2) Armstrong, Wall  
Comments
Frech> XF:sniffit-lmail-bo | Christey> This issue was rediscovered. | ADDREF BUGTRAQ:20020119 remote buffer overflow in sniffit | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101167452712383&w=2 | ADDREF BUGTRAQ:20000525 `sniffit -L mail" vulnerabilities | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95928090612990&w=2 | | I reviewed the patch that was claimed in the 20020119 Bugtraq | post, and it could well address the issue. However, since the | patch is also dated around the time of the original Bugtraq | post, *and* it says that it"s addressing an issue that"s | discussed on Bugtraq, that is sufficient to establish | acknowledgement. | CHANGE> [Christey changed vote from NOOP to MODIFY] | Christey> XF:sniffit-normmail-l-bo(7933) | URL:http://www.iss.net/security_center/static/7933.php