10
CVSSv2

CVE-2000-0091

Published: 21/01/2000 Updated: 10/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in vchkpw/vpopmail POP authentication package allows remote malicious users to gain root privileges via a long username or password.

Vulnerable Product Search on Vulmon Subscribe to Product

inter7 vpopmail vchkpw_3.4.2

inter7 vpopmail vchkpw_3.4.3

inter7 vpopmail vchkpw_3.4.4

inter7 vpopmail vchkpw_3.4.5

inter7 vpopmail vchkpw_3.4.11

inter7 vpopmail vchkpw_3.4.6

inter7 vpopmail vchkpw_3.4.8

inter7 vpopmail vchkpw_3.4.1

inter7 vpopmail vchkpw_3.4.7

inter7 vpopmail vchkpw_3.4.9

Exploits

source: wwwsecurityfocuscom/bid/942/info Vpopmail (vchkpw) is free GPL software package built to help manage virtual domains and non /etc/passwd email accounts on Qmail mail servers This package is developed by Inter7 (Referenced in the 'Credit' section) and is not shipped, maintained or supported by the main Qmail distribution Certai ...