10
CVSSv2

CVE-1999-0920

Published: 26/05/1999 Updated: 09/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote malicious users to gain privileges via the FOLD command.

Vulnerable Product Search on Vulmon Subscribe to Product

university of washington imap 4.4

university of washington pop2d

Exploits

source: wwwsecurityfocuscom/bid/283/info A buffer overflow vulnerability in pop2d version 44 or earlier allow malicious remote users to obtain access to the "nobody" user account The pop2 and pop3 servers support the concept of an "anonymous proxy", whereby a remote user connecting to the server can instruct it to open an IMAP mailbox ...