Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Qpopper Remote Memory Corruption Vulnerability

A memory corruption vulnerability has been discovered in Qpopper version 4.0.4 and earlier.

The vulnerability occurs when calling the 'mdef' command and a malicious macro name is supplied. By filling a target buffer with a malicious macro name it may be possible to trigger a procedure that would cause sensitive memory to be corrupted. The problem occurs due to the lack of NULL termination by the Qvsnprintf() function.

Successful exploitation of this issue may allow a remote attacker to execute arbitrary commands with the privileges of the Qpopper service.







 

Privacy Statement
Copyright 2008, SecurityFocus