4.6
CVSSv2

CVE-2001-1487

Published: 31/12/2001 Updated: 11/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

popauth utility in Qualcomm Qpopper 4.0 and previous versions allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option.

Vulnerable Product Search on Vulmon Subscribe to Product

qualcomm qpopper

Exploits

source: wwwsecurityfocuscom/bid/3710/info Qpopper is a freely available, open source Post Office Protocol server It is maintained and distributed by Qualcomm When popauth is executed with the trace option, it does not correctly handle user-supplied input A user can supply data to the popauth program through the trace flag which will c ...