10
CVSSv2

CVE-1999-0042

Published: 07/04/1997 Updated: 17/08/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in University of Washington's implementation of IMAP and POP servers.

Vulnerable Product Search on Vulmon Subscribe to Product

university of washington pop 3

university of washington imap 4

ibm aix 4.2.1

redhat linux 2.0

caldera openlinux 1.0

bsdi bsd os 3.0

bsdi bsd os 2.1

redhat linux 4.0

Exploits

/* This is the remote exploit of the hole in the imap daemon, for Linux The instruction code is doing open(), write(), and close() system calls, and it adds a line root::0:0 at the beggining of /etc/passwd (change to /etc/shadow if needed) The code needs to be self modifying since imapd turns everything to lowercase before it p ...