CVE-2008-1054 describes a stack-based buffer overflow vulnerability affecting NetWin SurgeMail versions 38k4 and earlier, and beta 39a. This flaw resides in the _lib_spawn_user_getpid function within swatch.exe and surgemail.exe, triggered by HTTP requests containing multiple long headers to webmail.exe and other CGI executables. The vulnerability carries a CVSS score of 6.4, indicating a medium severity. It is remotely exploitable with low attack complexity, requiring no authentication. Successful exploitation can lead to a denial of service (daemon crash) and potentially arbitrary code execution, impacting the availability and integrity of the affected system. While not listed on the KEV catalog or Hot List, exploit code for this vulnerability is publicly available on ExploitDB. Despite this, there is no evidence of active exploitation, and the CVE has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8aCPE matchmatch criteria | cpe:2.3:a:netwin:surgemail:1.8a:*:*:*:*:*:*:* | ||
1.8b3CPE matchmatch criteria | cpe:2.3:a:netwin:surgemail:1.8b3:*:*:*:*:*:*:* | ||
1.8dCPE matchmatch criteria | cpe:2.3:a:netwin:surgemail:1.8d:*:*:*:*:*:*:* | ||
1.8eCPE matchmatch criteria | cpe:2.3:a:netwin:surgemail:1.8e:*:*:*:*:*:*:* | ||
1.8g3CPE matchmatch criteria | cpe:2.3:a:netwin:surgemail:1.8g3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.