CVE-2001-1078
Summary
| CVE | CVE-2001-1078 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2001-06-21 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Extremail | Extremail | 1.0 | All | All | All |
| Application | Extremail | Extremail | 1.0.1 | All | All | All |
| Application | Extremail | Extremail | 1.0.2 | All | All | All |
| Application | Extremail | Extremail | 1.0.3 | All | All | All |
| Application | Extremail | Extremail | 1.1 | All | All | All |
| Application | Extremail | Extremail | 1.1.1 | All | All | All |
| Application | Extremail | Extremail | 1.1.2 | All | All | All |
| Application | Extremail | Extremail | 1.1.3 | All | All | All |
| Application | Extremail | Extremail | 1.1.4 | All | All | All |
| Application | Extremail | Extremail | 1.1.5 | All | All | All |
| Application | Extremail | Extremail | 1.1.6 | All | All | All |
| Application | Extremail | Extremail | 1.1.7 | All | All | All |
| Application | Extremail | Extremail | 1.1.8 | All | All | All |
| Application | Extremail | Extremail | 1.1.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| archives.neohapsis.com/archives/bugtraq/2001-06/0291.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| eXtremail Remote Format String Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| eXtremail mail server home page | af854a3a-2127-422b-91ae-364da2661108 | www.extremail.com | |
| www.extremail.com/history.htm | af854a3a-2127-422b-91ae-364da2661108 | www.extremail.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.