5.5
CVSSv3

CVE-2000-1198

Published: 31/08/2001 Updated: 08/02/2024
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.

Vulnerable Product Search on Vulmon Subscribe to Product

qualcomm qpopper 2.53

qualcomm qpopper 3.0

Exploits

source: wwwsecurityfocuscom/bid/1132/info Vulnerabilities exist in a number of pop3 daemon implementations, having to do with their creation of lock files Affected include Qualcomm's qpopper, and the popd included as part of the imap-4 rpm from RedHat Lockfiles in both implementation are created with consistent local file names; the Red ...