Qpopper Remote Memory Corruption Vulnerability
BID:7058
Info
Qpopper Remote Memory Corruption Vulnerability
| Bugtraq ID: | 7058 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0143 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | The discovery of this vulnerability has been credited to Florian Heinz <[email protected]>. |
| Vulnerable: |
Sun Cobalt RaQ XTR Qualcomm qpopper 4.0.4 Qualcomm qpopper 4.0.3 Qualcomm qpopper 4.0.2 Qualcomm qpopper 4.0.1 |
| Not Vulnerable: |
Qualcomm qpopper 4.0.5 fc2 |
Discussion
Qpopper Remote Memory Corruption Vulnerability
A memory corruption vulnerability has been discovered in Qpopper version 4.0.4 and earlier.
The vulnerability occurs when calling the 'mdef' command and a malicious macro name is supplied. By filling a target buffer with a malicious macro name it may be possible to trigger a procedure that would cause sensitive memory to be corrupted. The problem occurs due to the lack of NULL termination by the Qvsnprintf() function.
Successful exploitation of this issue may allow a remote attacker to execute arbitrary commands with the privileges of the Qpopper service.
A memory corruption vulnerability has been discovered in Qpopper version 4.0.4 and earlier.
The vulnerability occurs when calling the 'mdef' command and a malicious macro name is supplied. By filling a target buffer with a malicious macro name it may be possible to trigger a procedure that would cause sensitive memory to be corrupted. The problem occurs due to the lack of NULL termination by the Qvsnprintf() function.
Successful exploitation of this issue may allow a remote attacker to execute arbitrary commands with the privileges of the Qpopper service.
Exploit / POC
Qpopper Remote Memory Corruption Vulnerability
A proof of concept exploit has been made available:
A proof of concept exploit has been made available:
References
Qpopper Remote Memory Corruption Vulnerability
References:
References:
- Chrooting daemons and system processes HOW-TO (Network Dweebs)
- Qpopper Homepage (Qualcomm)
- RaQ XTR Patch Page (Sun)
- QPopper 4.0.x buffer overflow vulnerability (Florian Heinz
) - Re: QPopper 4.0.x buffer overflow vulnerability (Randall Gellens
) - Re: QPopper 4.0.x buffer overflow vulnerability (Jaroslaw Zachwieja
) - RE: QPopper 4.0.x buffer overflow vulnerability ("Jonathan A. Zdziarski"
) - Re: QPopper 4.0.x buffer overflow vulnerability (Harald Hellmuth
)