7.2
CVSSv2

CVE-2005-1151

Published: 25/05/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

qpopper 4.0.5 and previous versions does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or create arbitrary files as root.

Vulnerable Product Search on Vulmon Subscribe to Product

debian qpopper 4.0.5

debian qpopper

Vendor Advisories

This advisory does only cover updated packages for Debian 30 alias woody For reference below is the original advisory text: Two bugs have been discovered in qpopper, an enhanced Post Office Protocol (POP3) server The Common Vulnerabilities and Exposures project identifies the following problems: CAN-2005-1151 Jens Steube discovered that wh ...