7.5
CVSSv2

CVE-2000-0442

Published: 24/05/2000 Updated: 10/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Qpopper 2.53 and previous versions allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.

Vulnerable Product Search on Vulmon Subscribe to Product

qualcomm qpopper 2.52

sun cobalt raq 2

sun cobalt raq 3i

qualcomm qpopper 2.53

Exploits

source: wwwsecurityfocuscom/bid/1242/info A vulnerability exists in version 253 and prior of qpopper, a popular POP server, from Qualcomm By placing machine executable code in the X-UIDL header field, supplying formatting strings in the "From:" field in a mail header, and then issuing, as the user the mail was sent to, a 'euidl' command ...