qwikmail.sourceforge.netConfirmation
http://qwikmail.sourceforge.net/smtpd/qwik-smtpd-0.3.patch CVE-2004-2677
Qwik SMTP 0.3 - Format String
Record summary
CVE-2004-2677 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQwik SMTP 0.3 - Format StringExploitDB exploitby Carlos BarrosNot analyzed1 file
References
913037Third-party advisory
http://secunia.com/advisories/13037 1012016vdb entry
http://securitytracker.com/id?1012016 unl0ck.info
http://unl0ck.info/advisories/qwik-smtpd.txt 20070218 qwik-smtpd format stringmailing list
http://www.securityfocus.com/archive/1/460600/100/0/threaded 11572vdb entry
http://www.securityfocus.com/bid/11572 ADV-2007-0687vdb entry
http://www.vupen.com/english/advisories/2007/0687 qwik-smtpd-format-string(17917)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17917 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2677