← Back

CVE-2008-1054

nvd nist
Published: Feb 27, 2008Modified: Apr 23, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:P
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and beta 39a, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via an HTTP request with multiple long headers to webmail.exe and unspecified other CGI executables, which triggers an overflow when assigning values to environment variables. NOTE: some of these details are obtained from third party information.

Affected (27)

Products: Netwin: Surgemail
1 product
Surgemail
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Netwin
Version 1.8a
Version 1.8b3
Version 1.8d
Version 1.8e
Version 1.8g3
Version 1.9
Version 1.9b2
Version 2.0a2
Version 2.0c
Version 2.0e
Version 2.0g2
Version 2.1a
Version 2.1c7
Version 2.2a6
Version 2.2c10
Version 2.2c9
Version 2.2g2
Version 2.2g3
Version 3.0a
Version 3.0c2
Version 3.1s
Version 3.8f3
Version 3.8i2
Version 3.8i3
Version 3.8i
Version 38k4
Version 38k

References (16)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.