>> Symantec Mail Security for SMTP Header Handling Remote Code Execution Vulnerability
Title : Symantec Mail Security for SMTP Header Handling Remote Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-0799 CVE ID : CVE-2007-1252
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-03-02
Technical Description
A vulnerability has been identified in Symantec Mail Security for SMTP, which could be exploited by attackers or worms to take complete control of an affected system. This issue is due to a buffer overflow error when handling malformed email headers, which could be exploited by remote attackers or malware to execute arbitrary commands with SYSTEM privileges by sending a specially crafted email message through a vulnerable application.