20000523 Qpopper 2.53 remote problem, user can gain gid=mailmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-05/0267.html CVE-2000-0442
Cobalt RaQ 2.0/3.0 / qpopper 2.52/2.53 - 'EUIDL' Format String Input
Record summary
CVE-2000-0442 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCobalt RaQ 2.0/3.0 / qpopper 2.52/2.53 - 'EUIDL' Format String InputExploitDB exploitby PrizmNot analyzed1 file
References
420000608 pop <= 2000.3.4Vendor advisory
http://www.novell.com/linux/security/advisories/suse_security_announce_51.html 1242vdb entry
http://www.securityfocus.com/bid/1242 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0442