BugTraq
Qpopper v4.0.x poppassd local root exploit Apr 28 2003 02:12PM
dong-h0un U (xploit hackermail com) (1 replies)
Re: Qpopper v4.0.x poppassd local root exploit Apr 30 2003 11:35AM
Randall Gellens (rg_public 1 flagg qualcomm com)
I'm working on a fix, but would like to point out that poppassd is
not built nor installed by default. Also, poppassd is an inherently
insecure protocol that sends both the current and new passwords in
the clear, and in general should only be used with full understanding
of the situation.
--
Randall Gellens
rg_public.1 (at) flagg.qualcomm (dot) com [email concealed]
Opinions are personal; facts are suspect; I speak for myself only

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus