Qualcomm POP Server Buffer Overflow Vulnerability
BID:133
Info
Qualcomm POP Server Buffer Overflow Vulnerability
| Bugtraq ID: | 133 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-0006 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 1998 12:00AM |
| Updated: | Jul 06 2007 07:47PM |
| Credit: | The original warning about the widespread availability of an exploit for this vulnerability was posted to Bugtraq by Seth McGann ([email protected]) on June 27th, 1998. Discussion continued on Bugtraq for several weeks thereafter. An exploit for Linux was post |
| Vulnerable: |
Qualcomm qpopper 2.4 |
| Not Vulnerable: | |
Discussion
Qualcomm POP Server Buffer Overflow Vulnerability
A number of buffer-overflow issues reside in versions prior to 2.5 of Qualcomm's 'qpopper' program. Exploiting this issue allows a remote attacker to execute arbitrary commands on hosts that are running a vulnerable version.
To determine if you are vulnerable, telnet to port 110 on the possibly vulnerable host. A banner appears, informing you of the version of the pop server. For example:
% telnet yourmailhost.your.domain.com 110
Trying 123.123.123.123
Connected to mailhost
+OK QPOP (version 2.4) at yourmailhost.your.domain.com starting
If any version prior to 2.5 is reported, including 2.5 beta, you should upgrade immediately to the latest version.
A number of buffer-overflow issues reside in versions prior to 2.5 of Qualcomm's 'qpopper' program. Exploiting this issue allows a remote attacker to execute arbitrary commands on hosts that are running a vulnerable version.
To determine if you are vulnerable, telnet to port 110 on the possibly vulnerable host. A banner appears, informing you of the version of the pop server. For example:
% telnet yourmailhost.your.domain.com 110
Trying 123.123.123.123
Connected to mailhost
+OK QPOP (version 2.4) at yourmailhost.your.domain.com starting
If any version prior to 2.5 is reported, including 2.5 beta, you should upgrade immediately to the latest version.
Exploit / POC
Qualcomm POP Server Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Qualcomm POP Server Buffer Overflow Vulnerability
Solution:
Upgrade to the most current version of qpopper, which is available at:
ftp://ftp.qualcomm.com/
Individual vendor responses can be found in CERT advisory CA-98.08.
Solution:
Upgrade to the most current version of qpopper, which is available at:
ftp://ftp.qualcomm.com/
Individual vendor responses can be found in CERT advisory CA-98.08.
References
Qualcomm POP Server Buffer Overflow Vulnerability
References:
References: