This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of software utilizing SurgeMail Mail Server. The vulnerability is caused due to a boundary error within SurgeMail Mail Server. A buffer overflow vulnerability is located in the function which handles the real CGI executables. This can be exploited to cause a stack-based buffer overflow via an overly long, specially-crafted argument passed to this module.
This module exploits a local privilege escalation vulnerability in certain packages shipped with Sun xVM VirtualBox for the Linux platform. After successful exploitation an agent running as root will be installed.