Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.10184
Category:Gain root remotely
Title:Various pop3 overflows
Summary:NOSUMMARY
Description:Description:

The remote POP3 server might be vulnerable to a buffer overflow
bug when it is issued at least one of these commands, with a too long
argument :

auth
user
pass

If confirmed, this problem might allow an attacker to execute
arbitrary code on the remote system, thus giving him an interactive
session on this host.

Solution : If you do not use POP3, disable this service in /etc/inetd.conf
and restart the inetd process. Otherwise, upgrade to a newer version.

See also : http://online.securityfocus.com/archive/1/27197
Risk factor : High

Cross-Ref: BugTraq ID: 2781
BugTraq ID: 2811
BugTraq ID: 4055
BugTraq ID: 4295
BugTraq ID: 4614
BugTraq ID: 4789
BugTraq ID: 790
BugTraq ID: 830
BugTraq ID: 894
BugTraq ID: 942
Common Vulnerability Exposure (CVE) ID: CVE-2002-0799
http://www.securityfocus.com/bid/4789
Bugtraq: 20020521 YoungZSoft CMailServer overflow, PATCH + WAREZ!@#! (Google Search)
http://online.securityfocus.com/archive/1/273512
http://www.iss.net/security_center/static/9132.php
Common Vulnerability Exposure (CVE) ID: CVE-1999-0822
http://www.securityfocus.com/bid/830
Bugtraq: 19991130 qpop3.0b20 and below - notes and exploit (Google Search)
Bugtraq: 19991130 serious Qpopper 3.0 vulnerability (Google Search)
CopyrightThis script is Copyright (C) 1999 Renaud Deraison

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.