20040417 Squirrelmail Chpasswod bofmailing list
http://marc.info/?l=bugtraq&m=108222863917958&w=2 CVE-2004-0524
SquirrelMail - 'chpasswd' Local Buffer Overflow
Record summary
CVE-2004-0524 has a selected CVSS score of 10.0; EIP currently links 2 catalogued exploits.
Description
Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local users to gain root privileges via a long user name.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBSquirrelMail - 'chpasswd' Local Buffer OverflowExploitDB exploitby x314Not analyzed1 file
ExploitDBSquirrelMail - 'chpasswd' Local Privilege Escalation (Brute Force)ExploitDB exploitby BytesNot analyzed1 file
References
720040427 Re: Squirrelmail Chpasswod bofmailing list
http://marc.info/?l=bugtraq&m=108311782032370&w=2 11415Third-party advisory
http://secunia.com/advisories/11415 10166vdb entry
http://www.securityfocus.com/bid/10166 squirrelmail.orgConfirmation
http://www.squirrelmail.org/plugin_view.php?id=117 squirrelmail-chpasswd-binary-bo(15889)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15889 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0524