Record summary

CVE-2003-0143 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.

Description

The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBQpopper 4.0.x - Remote Memory CorruptionExploitDB exploitby Florian HeinzNot analyzed1 file
ExploitDB

PoC details

References

9