NJStar Security Information
| 2011-11-05: Security Vulnerability Found and Fixed in NJStar MiniSMTP Server |
|
A security researcher (Dillon Beresford) has identified a security vulnerability in NJStar MiniSMTP Server version 1.33 or older. MiniSMTP.exe is included for sending emails in the following 4 NJStar software: 1. NJStar Communicator v2.x and v3.0. The vulnerability is caused due to a boundary error in the handling of SMTP communication. This can be exploited remotely to cause a stack-based buffer overflow and execute arbitrary code if,
This vulnerability has been fixed by safe guarding all buffers and dis-allowing all SMTP connections form Internet. All users of NJStar Software (shareware or registered versions) are recommended to update each of the installed NJStar Software to the latest versions (x.x.11918), or download a single MiniSMTP v3.0 upgrade below to update all installed NJStar Software. ALL NJSTAR SOFTWARE USERS PLEASE INSTALL FOLLOWING UPGRADE
|

