Vulnerability Description
Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ftnapps | Crashmail Ii | <= 1.6 |
Related Weaknesses (CWE)
References
- http://exploitpack.comNot Applicable
- http://ftnapps.sourceforge.net/crashmail.htmlProduct
- https://www.exploit-db.com/exploits/44331ExploitVDB Entry
- https://www.vulncheck.com/advisories/crashmail-stack-based-buffer-overflow-remotThird Party Advisory
FAQ
What is CVE-2018-25223?
CVE-2018-25223 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads wi...
How severe is CVE-2018-25223?
CVE-2018-25223 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-25223?
Check the references section above for vendor advisories and patch information. Affected products include: Ftnapps Crashmail Ii.