20030310 QPopper 4.0.x buffer overflow vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=104739841223916&w=2 CVE-2003-0143
Qpopper 4.0.x - Remote Memory Corruption
Record summary
CVE-2003-0143 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQpopper 4.0.x - Remote Memory CorruptionExploitDB exploitby Florian HeinzNot analyzed1 file
References
920030312 Re: QPopper 4.0.x buffer overflow vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=104748775900481&w=2 20030314 [OpenPKG-SA-2003.018] OpenPKG Security Advisory (qpopper)mailing list
http://marc.info/?l=bugtraq&m=104768137314397&w=2 GLSA-200303-12Vendor advisory
http://marc.info/?l=bugtraq&m=104792541215354&w=2 DSA-259Vendor advisory
http://www.debian.org/security/2003/dsa-259 SuSE-SA:2003:018Vendor advisory
http://www.novell.com/linux/security/advisories/2003_018_qpopper.html 7058vdb entry
http://www.securityfocus.com/bid/7058 qpopper-popmsg-macroname-bo(11516)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/11516 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0143