Executive brief
A vulnerability exists in the LISTSERV mailing list management software that could allow an attacker to take control of the server. LISTSERV is used by organizations to manage large-scale email distribution lists and discussion groups. By exploiting this flaw, an unauthorized user could execute malicious commands, potentially leading to data theft or a complete system takeover.
Technical details
A buffer overflow vulnerability exists in the LISTSERV mailing list manager. The flaw is triggered when the application fails to properly validate the length of input data before copying it into a fixed-size memory buffer. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the LISTSERV service. Successful exploitation allows for arbitrary code execution with the privileges of the LISTSERV process, potentially leading to full system compromise. This is a legacy vulnerability originally identified in the late 1990s.
Affected products
- L-Soft LISTSERV mailing list manager
Timeline
- 1997-01-01: disclosed: Initial publication date in NVD.