Qualcomm QPopper Bulletin Name Buffer Overflow Vulnerability
BID:4614
Info
Qualcomm QPopper Bulletin Name Buffer Overflow Vulnerability
| Bugtraq ID: | 4614 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 28 2002 12:00AM |
| Updated: | Apr 28 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Marcell Fodor <[email protected]>. |
| Vulnerable: |
Qualcomm qpopper 4.0.4 Qualcomm qpopper 4.0.3 |
| Not Vulnerable: | |
Discussion
Qualcomm QPopper Bulletin Name Buffer Overflow Vulnerability
QPopper is a freely available, open source software package distributed by Qualcomm. It is designed for use on various operating systems, although this problem affects the Unix and Linux platforms.
QPopper does not sufficiently check bounds on some data. When a user supplies a bulletin with a long name (greater than 256 bytes), a buffer overflow occurs. This could result in the overwriting of process memory, including the return address within the stack, and code execution.
QPopper is a freely available, open source software package distributed by Qualcomm. It is designed for use on various operating systems, although this problem affects the Unix and Linux platforms.
QPopper does not sufficiently check bounds on some data. When a user supplies a bulletin with a long name (greater than 256 bytes), a buffer overflow occurs. This could result in the overwriting of process memory, including the return address within the stack, and code execution.
Exploit / POC
Qualcomm QPopper Bulletin Name Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Qualcomm QPopper Bulletin Name Buffer Overflow Vulnerability
Solution:
Caldera has issued fixes.
---
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Qualcomm qpopper 4.0.3
Qualcomm qpopper 4.0.4
Solution:
Caldera has issued fixes.
---
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Qualcomm qpopper 4.0.3
-
Caldera CSSA-2002-SCO.20
ftp://stage.caldera.com/pub/security/openserver/CSSA-2002-SCO.20/
Qualcomm qpopper 4.0.4
-
Caldera CSSA-2002-SCO.20
ftp://stage.caldera.com/pub/security/openserver/CSSA-2002-SCO.20/
References
Qualcomm QPopper Bulletin Name Buffer Overflow Vulnerability
References:
References:
- Qpopper Homepage (Qualcomm)